All of lore.kernel.org
 help / color / mirror / Atom feed
From: KOVACS Krisztian <hidden@balabit.hu>
To: Marc Schoechlin <ms@256bit.org>
Cc: netfilter@lists.netfilter.org
Subject: Re: building a iptables-firewallcluster
Date: Mon, 22 Aug 2005 13:50:48 +0200	[thread overview]
Message-ID: <200508221350.48867@nienna> (raw)
In-Reply-To: <20050821133749.GB20106@256bit.org>


  Hi,

On Sunday 21 August 2005 15.37, Marc Schoechlin wrote:
> > Is this now part of the linux-kernel or are there now other
> > strategies to build firewallclusters for load-balancing and/or
> > high-availability ?
> >
> > Where can i get detailed information about the installation of a
> > iptables-based firewall-cluster ?
>
> No resonse for two weeks - am i right to assume that this
> project is dead ?

  Almost, but not completely dead.

  Current code can be found in the netfilter SVN repository, take a look 
at these URLs:
 
http://svn.netfilter.org/cgi-bin/viewcvs.cgi/branches/netfilter-ha/linux-2.6/
http://svn.netfilter.org/cgi-bin/viewcvs.cgi/branches/netfilter-ha/linux-2.6-actact/

  The linux-2.6 branch is the current (actually quite old) code for 
2.6.10; the linux-2.6-actact branch is Harald's latest development 
version (configurable through sysfs, capable of participating in 
multiple sync groups, etc.). This latter branch is even more 
experimental than the linux-2.6 branch, of course...

  Some of the infrastructure necessary for this code (namely conntrack 
events) will be part of Linux 2.6.14 (it's already in David Miller's 
2.6.14 networking branch). Unfortunately Harald's -actact branch is far 
from being complete, and porting this code for the (slightly changed) 
Linux-2.6.14 infrastructure is to be done. Slightly more information 
can be found in the netfilter-ha mailing list archive (yes, I know, 
that list seems to be dead as well).

  Unfortunately Harald does not seem to have the time necessary to work 
on this project right now, and neither do I. (Apart from this, I also 
don't have the devices necessary to do _any_ testing apart from 
compiling the code...)

  Sorry for the late answer, but the case is that I very rarely read the 
'netfilter' mailing list.

-- 
 Regards,
  Krisztian Kovacs


  parent reply	other threads:[~2005-08-22 11:50 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-08-02 12:03 building a iptables-firewallcluster Marc Schoechlin
2005-08-21 13:37 ` Marc Schoechlin
2005-08-22  4:10   ` Grant Taylor
2005-08-22 11:50   ` KOVACS Krisztian [this message]
2005-08-22 13:15     ` /dev/rob0
2005-08-22 14:42       ` KOVACS Krisztian
2005-08-22 18:29       ` Taylor, Grant
2005-08-22 18:26     ` Taylor, Grant

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200508221350.48867@nienna \
    --to=hidden@balabit.hu \
    --cc=ms@256bit.org \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.