请教DR模式的转发问题

请教各位:
我用5个节点建立了一个LVS集群提供FTP下载服务,其中一台做调度服务器,其余四台做后台真实服务器,向外提供服务的VIP为174.69.4.13,后台的真实IP为174.69.4.8/9/10/11, 从5月起放在公网上一直测试到前几天.
在测试过程中,用ipvsadm -Lcn查看连接状态时,发现TCP的连接状态有11万多行,感觉实在是太多.其中TCP的状态大多为CLOSE和NONE,且有许多0端口.我对TCP的状态机不是很了解,请问这是正常的吗? 截取其中的一段为:
TCP 00:40 CLOSE 221.234.251.142:2513 174.69.4.13:47637 174.69.4.11:47637
TCP 00:37 CLOSE 221.218.144.143:4597 174.69.4.13:44229 174.69.4.9:44229
TCP 00:37 CLOSE 58.49.139.40:4111 174.69.4.13:23701 174.69.4.10:23701
TCP 00:31 CLOSE 222.160.161.2:1872 174.69.4.13:18307 174.69.4.11:18307
TCP 00:29 FIN_WAIT 221.221.229.206:65423 174.69.4.13:64438 174.69.4.8:64438
TCP 00:28 CLOSE 222.64.29.2:1617 174.69.4.13:38046 174.69.4.8:38046
TCP 00:23 FIN_WAIT 61.51.63.110:2139 174.69.4.13:17420 174.69.4.11:17420
TCP 00:22 CLOSE 218.95.95.170:4091 174.69.4.13:17408 174.69.4.8:17408
TCP 00:20 CLOSE 222.181.195.145:4008 174.69.4.13:49678 174.69.4.10:49678
TCP 00:19 CLOSE 58.34.89.142:60256 174.69.4.13:34798 174.69.4.11:34798
TCP 00:18 CLOSE 60.221.9.30:4907 174.69.4.13:34886 174.69.4.9:34886
TCP 00:15 CLOSE 60.181.245.178:23521 174.69.4.13:38817 174.69.4.11:38817
TCP 00:14 CLOSE 222.149.21.163:1631 174.69.4.13:59617 174.69.4.9:59617
TCP 00:10 CLOSE 58.48.157.77:2320 174.69.4.13:33919 174.69.4.11:33919
TCP 00:08 CLOSE 61.143.215.191:1240 174.69.4.13:46919 174.69.4.8:46919
TCP 00:02 CLOSE 218.95.164.220:2548 174.69.4.13:19308 174.69.4.11:19308
TCP 00:50 NONE 222.212.16.215:0 174.69.4.13:0 174.69.4.8:0
TCP 00:55 NONE 220.187.33.182:0 174.69.4.13:0 174.69.4.9:0
TCP 00:46 NONE 124.147.144.129:0 174.69.4.13:0 174.69.4.9:0
TCP 00:19 NONE 58.62.32.145:0 174.69.4.13:0 174.69.4.10:0
TCP 00:49 NONE 221.211.4.30:0 174.69.4.13:0 174.69.4.8:0
TCP 00:14 NONE 222.92.150.241:0 174.69.4.13:0 174.69.4.9:0
TCP 00:28 NONE 58.63.158.49:0 174.69.4.13:0 174.69.4.9:0
TCP 00:58 CLOSE 218.72.40.49:48049 174.69.4.13:50258 174.69.4.10:50258
TCP 00:56 CLOSE 222.211.118.51:4514 174.69.4.13:65132 174.69.4.11:65132
TCP 00:55 CLOSE 220.235.80.138:1659 174.69.4.13:34313 174.69.4.8:34313
TCP 00:53 FIN_WAIT 201.47.218.50:61548 174.69.4.13:46438 174.69.4.8:46438
TCP 00:49 CLOSE 60.179.9.67:1647 174.69.4.13:59888 174.69.4.11:59888
TCP 00:49 ESTABLISHED 222.47.7.177:3124 174.69.4.13:17781 174.69.4.9:17781
TCP 00:47 FIN_WAIT 222.242.68.71:3722 174.69.4.13:29329 174.69.4.8:29329
TCP 00:41 FIN_WAIT 218.26.20.99:2075 174.69.4.13:40655 174.69.4.11:40655
TCP 00:35 CLOSE 125.89.20.211:1514 174.69.4.13:11117 174.69.4.8:11117
TCP 00:35 FIN_WAIT 222.173.17.196:26042 174.69.4.13:64626 174.69.4.8:64626
TCP 00:33 CLOSE 60.182.100.74:3948 174.69.4.13:7651 174.69.4.9:7651
TCP 00:27 CLOSE 221.227.203.62:3364 174.69.4.13:42499 174.69.4.11:42499
TCP 00:26 CLOSE 61.141.152.160:1980 174.69.4.13:13913 174.69.4.10:13913
TCP 00:21 CLOSE 60.213.182.176:2758 174.69.4.13:58315 174.69.4.8:58315
TCP 00:18 CLOSE 61.131.73.35:13559 174.69.4.13:33458 174.69.4.11:33458
TCP 00:14 CLOSE 60.22.70.185:1067 174.69.4.13:60158 174.69.4.9:60158
TCP 00:11 CLOSE 60.183.100.42:26533 174.69.4.13:57325 174.69.4.11:57325
TCP 00:09 CLOSE 59.54.234.188:4826 174.69.4.13:23808 174.69.4.9:23808
TCP 00:08 CLOSE 220.187.96.10:2437 174.69.4.13:11976 174.69.4.8:11976
TCP 00:05 CLOSE 221.237.50.187:1057 174.69.4.13:10167 174.69.4.10:10167
TCP 00:05 CLOSE 222.209.14.19:13865 174.69.4.13:27110 174.69.4.10:27110
TCP 00:03 CLOSE 60.9.96.188:3898 174.69.4.13:65088 174.69.4.10:65088
TCP 00:01 CLOSE 60.166.230.243:3713 174.69.4.13:47449 174.69.4.10:47449
TCP 00:32 NONE 60.5.100.84:0 174.69.4.13:0 174.69.4.11:0
TCP 00:50 NONE 221.201.150.21:0 174.69.4.13:0 174.69.4.10:0
TCP 00:27 NONE 220.163.236.91:0 174.69.4.13:0 174.69.4.11:0
TCP 00:43 NONE 218.83.122.4:0 174.69.4.13:0 174.69.4.9:0
TCP 00:33 NONE 218.2.10.155:0 174.69.4.13:0 174.69.4.11:0
TCP 00:31 NONE 60.201.198.7:0 174.69.4.13:0 174.69.4.9:0
TCP 00:55 FIN_WAIT 59.40.59.15:3336 174.69.4.13:47638 174.69.4.10:47638
TCP 00:49 ESTABLISHED 221.220.215.44:59457 174.69.4.13:19986 174.69.4.9:19986
TCP 00:47 CLOSE 222.132.108.242:4892 174.69.4.13:49315 174.69.4.10:49315
TCP 00:44 CLOSE 220.165.208.250:3660 174.69.4.13:50446 174.69.4.9:50446
TCP 00:42 CLOSE 222.209.83.194:2415 174.69.4.13:54787 174.69.4.10:54787
TCP 00:41 CLOSE 61.149.121.56:61188 174.69.4.13:49077 174.69.4.8:49077
TCP 00:40 CLOSE 220.165.192.138:58092 174.69.4.13:27753 174.69.4.11:27753
TCP 00:40 CLOSE 221.228.204.9:4800 174.69.4.13:33399 174.69.4.9:33399
TCP 00:39 CLOSE 222.160.52.35:1419 174.69.4.13:38045 174.69.4.8:38045
TCP 00:37 CLOSE 220.168.77.142:2903 174.69.4.13:64001 174.69.4.11:64001
TCP 00:35 CLOSE 58.52.50.76:3674 174.69.4.13:8610 174.69.4.9:8610
TCP 00:34 FIN_WAIT 218.95.165.240:3053 174.69.4.13:27699 174.69.4.10:27699
TCP 00:34 CLOSE 221.210.218.37:1913 174.69.4.13:21237 174.69.4.11:21237
TCP 00:32 CLOSE 60.1.58.9:2288 174.69.4.13:14575 174.69.4.10:14575
TCP 00:29 CLOSE 222.93.43.37:2374 174.69.4.13:5312 174.69.4.10:5312
TCP 00:26 CLOSE 219.145.119.140:2437 174.69.4.13:60730 174.69.4.11:60730
TCP 00:19 CLOSE 220.188.84.166:2686 174.69.4.13:53450 174.69.4.10:53450
TCP 00:18 SYN_RECV 60.167.2.23:2766 174.69.4.13:21 174.69.4.11:21
TCP 00:15 CLOSE 221.217.169.1:1747 174.69.4.13:30087 174.69.4.9:30087
TCP 00:12 CLOSE 218.18.117.180:2467 174.69.4.13:38545 174.69.4.11:38545
TCP 00:09 CLOSE 61.49.153.21:4356 174.69.4.13:53391 174.69.4.10:53391
TCP 00:09 CLOSE 60.2.105.232:1997 174.69.4.13:19519 174.69.4.10:19519
TCP 00:00 CLOSE 59.40.85.43:3854 174.69.4.13:14059 174.69.4.11:14059
TCP 00:00 CLOSE 61.187.208.174:1321 174.69.4.13:44461 174.69.4.9:44461
TCP 00:41 NONE 222.160.163.136:0 174.69.4.13:0 174.69.4.11:0
TCP 00:03 NONE 218.24.57.120:0 174.69.4.13:0 174.69.4.11:0
TCP 00:34 NONE 222.92.142.221:0 174.69.4.13:0 174.69.4.11:0
TCP 00:32 NONE 220.166.197.240:0 174.69.4.13:0 174.69.4.9:0
TCP 00:19 NONE 219.135.179.240:0 174.69.4.13:0 174.69.4.9:0
TCP 00:57 CLOSE 58.49.139.200:3256 174.69.4.13:16804 174.69.4.10:16804
TCP 00:57 CLOSE 219.131.112.94:1778 174.69.4.13:16980 174.69.4.11:16980
TCP 00:56 CLOSE 220.187.84.156:2982 174.69.4.13:8625 174.69.4.9:8625

Forums:

应该是正常的。

TCP状态为NONE的是持久性模板,它是记录来自同一IP地址的访问调度到同一服务器。

TCP状态为CLOSE的是已关闭连接。

你可以查一下有没有处于ESTABLISHED的连接,例如"ipvsadm -Lcn | grep ESTABLISHED"。

现在基本上了解,谢谢wensong博士的指点

用ipvsadm -Lcn | grep ESTABLISHED 太慢,我记得当初统计出有2W多的时候很慢
后来还是用这个比较快:
cat /proc/net/ip_vs_conn|grep ESTABLISHED|wc -l

http://www.ourlinux.net