Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Isolated private network
PostPosted: Wed Jun 22, 2011 5:28 pm 
Offline
Junior Member

Joined: Mon Apr 18, 2011 1:54 pm
Posts: 45
Website: http://www.rassoc.com/gregr/weblog
I'm not holding my breath on this one, but I think it would be nice.

It would be cool if all of the nodes on my account, within a single data center, could have a "private" private network. Meaning they can all talk to each other, but no other incoming traffic (other than node balancers on my account) would be allowed.

Right now I'm building the deployment scripts to configure iptables to do something like this; however, it's a bit of a pain. If I have, say, 9 nodes, and I want to add a 10th node, I need to update the iptables config on all 10 nodes to make this work. Similarly, dropping a single node requires touching every server.

Thinking about this some more...as a less-awesome-but-ok alternative would be if I could be guaranteed that all of my nodes will come up with a private IP on my own subnet, in which case I could make a single rule that's shared among all the nodes. I confess I don't know if this is an option; I'll fire off a ticket to support to see.


Top
   
 Post subject:
PostPosted: Wed Jun 22, 2011 5:33 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
IPv6 pools get you your own subnet, and they work just like private IPs. Drop anything not from or to your IPv6 Pool subnet, and you're good, no?

-Chris


Top
   
 Post subject:
PostPosted: Wed Jun 22, 2011 5:44 pm 
Offline
Junior Member

Joined: Mon Apr 18, 2011 1:54 pm
Posts: 45
Website: http://www.rassoc.com/gregr/weblog
caker wrote:
IPv6 pools get you your own subnet, and they work just like private IPs. Drop anything not from or to your IPv6 Pool subnet, and you're good, no?

-Chris


You know, clearly I need to get smarter about IPv6, as all roads seem to lead there. That does seem like a reasonable solution.

I do wonder if all of our code can deal with parsing an IPv6 address at the moment...guess I should try it. :)

Thanks!


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
RSS

Powered by phpBB® Forum Software © phpBB Group