All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] Dead Gateway Detection & BGP
@ 2007-08-26 17:29 Rangi Biddle
  2007-08-27 14:42 ` Grant Taylor
                   ` (7 more replies)
  0 siblings, 8 replies; 9+ messages in thread
From: Rangi Biddle @ 2007-08-26 17:29 UTC (permalink / raw)
  To: lartc


[-- Attachment #1.1: Type: text/plain, Size: 2888 bytes --]

Greetings to all,

 

To start I’ll firstly lay down the foundation to what I have done so far and
if those of you on the list can provide further insight, tips, links etc.

 

This scenario consists of 2 firewalls (both running Debian “etch”), 2 Cisco
routers (unsure of model numbers) connected together like so in the diagram
below.

 

 

 
-----------------------

 
|  Uplink Provider  |

 
-----------------------

 
|

 
|

 
-----------------------

 
|                                    |

 
-------------------    --------------------

                                                                | Cisco
Router  |   |  Cisco Router   |

 
------------------      --------------------

 
|                                    |

 
|                                    |

 
-------------------    --------------------

                                                                |
Firewall 1     |   |      Firewall 2     |

 
-------------------     --------------------

 

Initially, the first task I was designated was to setup BGP routing on 2
firewalls.  Each firewall is connected to its own Cisco router provided by
the uplink provider and the uplink provider is only providing a default
gateway/router to each of the firewalls.  Now, having had minimal experience
with BGP (minimal in terms of the broadness of what is possible with BGP)
and using the information provided by the uplink provider I have setup BGP.

 

What I have been recently informed of is that the 2 firewalls must do some
sort of failover between them when either of the default gateway’s are no
longer responsive.  I had initially looked into using heartbeat (which I am
still considering) to do the failover or possibly using vrrpd (Virtual
Router Redundancy Protocol Daemon).  This however isn’t what I am contacting
this list about.  What I need to do at minimal, is at least for the
failover, is to detect when the default gateway of (say) firewall 1 is no
longer available and perform failover to firewall 2 and vice versa.  As far
as  I am aware the only DGD support available is still through the patches
that Julian Anastasov wrote for the 2.4 kernel series or by writing a script
that uses arping to determine the last hop available. 

 

What other options are there?

 

I have done a fair amount of searching the internet only to come back to
these 2 possibilities.  Surely there must be something else ….

 

Thanks in advance to anyone that replies as I know that this topic seems to
be coming up more and more frequently on the lists and must be getting
somewhat tedious for most.

 

Regards,

 

Rangi


No virus found in this outgoing message.
Checked by AVG Free Edition. 
Version: 7.5.484 / Virus Database: 269.12.8/973 - Release Date: 8/25/2007
5:00 PM
 

[-- Attachment #1.2: Type: text/html, Size: 13149 bytes --]

[-- Attachment #2: Type: text/plain, Size: 143 bytes --]

_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2007-08-30  3:58 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-26 17:29 [LARTC] Dead Gateway Detection & BGP Rangi Biddle
2007-08-27 14:42 ` Grant Taylor
2007-08-27 16:51 ` Grant Taylor
2007-08-27 17:21 ` Peter Rabbitson
2007-08-29  5:27 ` Grant Taylor
2007-08-29  5:40 ` Grant Taylor
2007-08-30  1:50 ` Rangi Biddle
2007-08-30  2:40 ` Grant Taylor
2007-08-30  3:58 ` Grant Taylor

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.