I've solved this problem by adding iptables rule that ACCEPT packets with state NEW and INVALID from source RealServer
Sorry, but I don't know exactly which chain could be added this rule in, because I use one chain for INPUT and FORWARD:
iptables -t filter -A INPUT-FORWARD -m state --state NEW,INVALID -m tcp -p tcp -s source --sport source_port -j ACCEPT
source and source_port are Real Servers and Ports that used in IPVS (LVS). For simplicity, I use source_net instead few sources
Hope it will help somebody!
By the way I use LVS-NAT
Last edited by AlekZandre; 12-05-2012 at 11:47 AM.
Reason: add info