Networking Forums

Networking Forums > Computer Networking > Linux Networking > redundant linux firewall

Reply
Thread Tools Display Modes

redundant linux firewall

 
 
Aditya Ivaturi
Guest
Posts: n/a

 
      06-10-2004, 02:56 PM
We have designed a custom ip-tables based linux firewall. This firewall
guards 3 web servers and a mail server. Recently it died on us due to a
faulty RAM module (in the hindsight we should have tested it). This prompted
us to look for a failover firewall which will eventually lead to a higly
available setup. This failover machine need not be identical in
configuration but the sessions and iptables etc need to be synced. I did
some research in to tools that'll help me do this and I came across a few
projects which address this in one way or the other. Linux-ha
(http://linux-ha.org/), Fake (http://www.vergenet.net/linux/fake/) and
UltraMonkey (http://www.ultramonkey.org/).

Any suggestions on which one might be a better solution for our situation or
are there any other projects which are better? Any light on some pros and
cons (from real world experience and not what is written on the web page)
would be great. Thanks.

--Turi


 
Reply With Quote
 
 
 
 
Menno Duursma
Guest
Posts: n/a

 
      06-19-2004, 02:22 PM
On Thu, 10 Jun 2004 09:56:39 -0500, Aditya Ivaturi wrote:

> [ ... ] sessions and iptables etc need to be synced.


http://cvs.netfilter.org/netfilter-ha/

[ Snip: Linux-HA ]

Look for "The failover of the load balancer" here:
http://www.linux-vs.org/HighAvailability.html

You need an aditional connection between the firewalls,
(for the "heartbeat"). In this kind of a setup though.

> Any suggestions on which one might be a better solution for our
> situation or are there any other projects which are better?


http://www.ucarp.org/

> Any light on some pros and cons (from real world experience and not what
> is written on the web page) would be great. Thanks.


Well, i guess this followup isn't great then ...

Why one would want to use: CARP rather then VRRP / HSRP :
http://www.openbsd.org/lyrics.html

--
-Menno.

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
linux failover (redundant internet/dial backup) mdiaczyk@yahoo.com Linux Networking 2 02-29-2008 01:55 AM
LINUX/shorewall firewall to firewall VPN question sundog@mountaindogs.net Linux Networking 3 03-14-2006 04:04 PM
Gigabit redundant firewall questions (hardware and software) David Schwartz Linux Networking 0 11-02-2004 06:00 AM
linux robust?can build application layer firewall on linux? happy Linux Networking 9 09-19-2004 06:54 PM
Firewall/router with redundant internet connection David Brown Linux Networking 2 08-02-2004 06:15 AM



1 2 3 4 5 6 7 8 9 10 11