From: Michael Schwartzkopff <ms@sys4.de>
To: netfilter <netfilter@vger.kernel.org>
Cc: Ricardo Klein <klein.rfk@gmail.com>
Subject: Re: Linux Firewall Active/Active
Date: Wed, 05 Nov 2014 20:40:42 +0100 [thread overview]
Message-ID: <4128127.KGiVEnbFtn@nb003> (raw)
In-Reply-To: <CADuigkVbB2nt5P6y-JCaW_bh6v_GhjL9BRBiHRyvA_yH81v4RA@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1621 bytes --]
Am Mittwoch, 5. November 2014, 17:15:23 schrieben Sie:
> Hi there,
>
> I need to build a scenario with 2 linux servers (probably CentOS7)
> acting as active/active firewall servers. What tools should I use?
> I saw some articles with:
> - conntrackd + keepalived
> - conntrackd + corosync + pacemaker
Why? There is not reasonable cause to build an active/active firewall from two
nodes.
Any single hardware is fast enough to filter the speed of a WAN connection you
can afford. No need for load balanceing.
If one server breaks, the other has to bear the whole load. So you have to
design your hardware for the whole load.
So please build an active/passive system.
keealive makes the things very simple. If you have just the firewall, go for
it. If you waht a little bit more, i.e. conntrackd and a squid with
dependencies amongst all resources, go for pacemaker.
> But, what is the most used/stable?
>
>
> AND, if there is a chance, I have 4 lan networks (each one in a
> different VLAN) and it should be good if I can set something like
> "preffered master" to each one for load distribution, because I will
> run SQUID in those servers too.
>
> I just need to know which way to go, so, I can learn the tools and
> configure it all here.
Mit freundlichen Grüßen,
Michael Schwartzkopff
--
[*] sys4 AG
http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044
Franziskanerstraße 15, 81669 München
Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 230 bytes --]
next prev parent reply other threads:[~2014-11-05 19:40 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-05 19:15 Linux Firewall Active/Active Ricardo Klein
2014-11-05 19:40 ` Michael Schwartzkopff [this message]
2014-11-05 19:50 ` Ricardo Klein
2014-11-05 19:57 ` Michael Schwartzkopff
2014-11-05 20:06 ` Ricardo Klein
2014-11-05 20:40 ` Arturo Borrero Gonzalez
2014-11-05 21:45 ` shawn wilson
2014-11-05 22:43 ` Paul Robert Marino
2014-11-05 23:55 ` Pablo Neira Ayuso
2014-11-06 14:37 ` Paul Robert Marino
2014-11-06 15:53 ` Pablo Neira Ayuso
2014-11-06 12:43 ` Robert Sander
2014-11-06 13:21 ` Arturo Borrero Gonzalez
2014-11-06 15:10 ` Paul Robert Marino
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4128127.KGiVEnbFtn@nb003 \
--to=ms@sys4.de \
--cc=klein.rfk@gmail.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox