All of lore.kernel.org
 help / color / mirror / Atom feed
* Redundant netfilter gateway
@ 2004-06-17 20:52 Patrick Ahler
  2004-06-17 21:02 ` B. McAninch
  2004-06-17 21:12 ` Primero
  0 siblings, 2 replies; 10+ messages in thread
From: Patrick Ahler @ 2004-06-17 20:52 UTC (permalink / raw)
  To: netfilter

I am looking for info on creating a redundant gateway/firewall. I
currently have my network setup with 1 working iptables gateway/firewall
and 1 backup gateway. If the first gateway goes down, I change the IP's
and spoof the MAC addresses (I change the external MAC address because
my internal network is masqueraded through the gateway and just
switching the external IP messes with the arp tables on the router...
That's a whole other issue though) on the backup gateway and it takes
over. This is not redundancy and is dirty. Does anyone have any
suggestions on how to do this better?

Patrick Ahler
Systems Administrator
Vikus Corporation 


^ permalink raw reply	[flat|nested] 10+ messages in thread
* RE: Redundant netfilter gateway
@ 2004-06-17 22:37 Daniel Chemko
  0 siblings, 0 replies; 10+ messages in thread
From: Daniel Chemko @ 2004-06-17 22:37 UTC (permalink / raw)
  To: Günter Zimmermann, B. McAninch; +Cc: Patrick Ahler, netfilter

> I think this is the only realy full redundant opensource firewall
> available. 

I've used linux-ha's heartbeatd in the past. I've had mixed results, so I can't recommend it before you try it. It does perform  automatic MAC failover with gratuitous arp's. I used it on a 5 net homed setup and I found issues with the takeover. Maybe a 2 network link would behave better.

SARU I believe was never actually implemented, or at least not yet. The Linux Virtual Server seems to have 'something' but I can't say that I know what it does. The netfilter module listed in their download page seems to indicate that its an active state failover.

Harald Welte is also developing a netfilter failover module, but I haven't heard much of that in the past 6 months.


^ permalink raw reply	[flat|nested] 10+ messages in thread
* RE: Redundant netfilter gateway
@ 2004-06-17 23:50 Patrick Ahler
  2004-06-17 23:56 ` Cedric Blancher
  0 siblings, 1 reply; 10+ messages in thread
From: Patrick Ahler @ 2004-06-17 23:50 UTC (permalink / raw)
  To: netfilter

 
I will definitely check out the linux virtual server. I'm surprised
there hasn't been more demand for a netfilter failover module though, I
know I would sleep better at night if there was. =)


Patrick Ahler
Systems Administrator
Vikus Corporation 

M 423.314.8910
W 423.954.3378
F 423.954.3375


^ permalink raw reply	[flat|nested] 10+ messages in thread
[parent not found: <20040619042840.20653.69114.Mailman@vishnu.netfilter.org>]

end of thread, other threads:[~2004-06-22  8:57 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-06-17 20:52 Redundant netfilter gateway Patrick Ahler
2004-06-17 21:02 ` B. McAninch
2004-06-17 21:22   ` Günter Zimmermann
2004-06-17 21:12 ` Primero
  -- strict thread matches above, loose matches on Subject: below --
2004-06-17 22:37 Daniel Chemko
2004-06-17 23:50 Patrick Ahler
2004-06-17 23:56 ` Cedric Blancher
2004-06-18  9:56   ` KOVACS Krisztian
     [not found] <20040619042840.20653.69114.Mailman@vishnu.netfilter.org>
2004-06-21 15:12 ` Luis Pacheco
2004-06-22  8:57   ` KOVACS Krisztian

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.