From: Kevin Dwyer <kevin@pheared.net>
To: Chip Upsal <cupsal@cyberwolf.com>
Cc: netfilter@lists.netfilter.org, linux-ha@muc.de
Subject: Re: Using heartbeat for fall over on IPTables Firewall
Date: Mon, 17 Mar 2003 14:11:56 -0500 [thread overview]
Message-ID: <20030317141156.579b5eed.kevin@pheared.net> (raw)
In-Reply-To: <3019863CF306D211BA4500A0CC30812DC67927@exchange.cyberwolf.com>
On Mon, 17 Mar 2003 09:16:46 -0700
Chip Upsal <cupsal@cyberwolf.com> wrote:
> I am looking to use heartbeat to provide fall over for my iptables
> firewall. I am looking for those with experience using these tools
> together.
>
> I plan to use RH7.2 on the firewalls.
I've been using a modified debian, but most distributions should be
fine.
> I made some attempts at implementing such a solution but i ran into a
> few problems.
>
> I would like suggestions on setup of the heartbeat configuration
> files. Pointers on the iptables startup script. and advice on what
> kernel version to use and if any patches need to be applied.
One way to do it is to setup heartbeat with ipfail. Consult the mailing
list archives and the documentation for more details.
You'll probably want a fairly generic ruleset that you can apply to both
firewalls. I've successfully done this by hand and with fwbuilder.
Depending on how you set things up you may or may not need a resource
script for heartbeat to execute when the firewall picks up the virtual
IP or loses it. I had to do this to handle problems with both machines
holding the same aliases for my NATs. Sometimes that will create some
ARP hell, but it's very situation dependent. If you need to do this,
consult the scripts that are installed in $sysconfdir/ha.d/resource.d/
for examples.
The one big thing that is missing from this setup is state table
replication. I've been interested in getting that working but the
nf-failover list has been quiet, and I haven't had a lot of free time to
poke at code. If anyone out there is interested in working on it, I'd
like to hear from you.
--
/* kevin@pheared.net http://pheared.net/devel/ */
/* Network Security Engineer http://pheared.net/~kevin */
/* Sabotage will set us free. Throw a rock in the machine. */
/* >++++++++++[<++++++++++>-]<.+++++.----.[-]++++++++++. */
next prev parent reply other threads:[~2003-03-17 19:11 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-03-17 16:16 Using heartbeat for fall over on IPTables Firewall Chip Upsal
2003-03-17 17:35 ` Marc Cluet
2003-03-17 19:11 ` Kevin Dwyer [this message]
-- strict thread matches above, loose matches on Subject: below --
2003-03-17 16:51 Antonio Paulo Salgado Forster
2003-03-17 20:39 ` Steve Mickeler
2003-03-17 18:55 Elmshauser, Erik
2003-03-17 21:44 Chip Upsal
2003-03-17 22:08 ` Steve Mickeler
2003-03-18 8:02 ` Cedric Blancher
2003-03-17 22:46 Antonio Paulo Salgado Forster
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030317141156.579b5eed.kevin@pheared.net \
--to=kevin@pheared.net \
--cc=cupsal@cyberwolf.com \
--cc=linux-ha@muc.de \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox