Linux Netfilter discussions
 help / color / mirror / Atom feed
* Conntrackd+Keepalived, active/active firewall cluster
@ 2011-06-06 22:08 CeR
  2011-08-02 20:26 ` Pablo Neira Ayuso
  0 siblings, 1 reply; 2+ messages in thread
From: CeR @ 2011-06-06 22:08 UTC (permalink / raw)
  To: netfilter

Hi there!
With the last package I got of conntrack-tools I see some config files
and shell scripts supposed to work in an active/active firewall
cluster.
Configuration files for keepalived are included.
I have configured my system in the way I guess it may work, but have
some doubts about the configuration and the system isn't working at
all.

Some issues:
· I think keepalived should give both nodes both IPV resources, so the
load balancing can be succefully done with iptables (as seen in
multiprimary.sh)
· With the give configuration, Keepalived sometimes gives IPV
resources to just one node, the other remains inactive and seems like
a passive-backup node.
· In some cases, I have both nodes with both IPV resources, but it
seems that some misconfiguration in iptables DROP packages needed by
clients connections through the firewall. Maybe conntrackd not working
properly in state replication?

If anyone gives me some clues I could just write some documentation
regarding this configuration, maybe with a little explanation of
protocols and tools being implied. Or is there already some
documentation?
As you can see, right now i'm working in a non-production environment,
but with more investigation and develop all can be done. I'm really
interested in this.
Best regards!

-- 
/* Arturo Borrero Gonzalez || cer.inet@linuxmail.org */
/* Use debian gnu/linux! Best OS ever! */

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-08-02 20:26 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-06-06 22:08 Conntrackd+Keepalived, active/active firewall cluster CeR
2011-08-02 20:26 ` Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox