[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: redundant firewall with openbsd



Shriman Gurung wrote...
> How redundant do you want to be?  I have a pair of boxes set up 
> so that one can assume the identity of the other in about 30 seconds
> (including about 25 seconds for the reboot ;)) but it doesn't 
> do anything like on-the-fly state table maintenance or virtualised 
> MAC addressing or VRRP or...

How did you set that up? I'm in the midst of building redundant
firewalls for my company, I was just going to write a simple
shell script which renumbured the spare box as the live box and rebooted
it (you'd power off the old box first).
The ipf/ipnat.rules files would be copied over anytime they are
changed, but something more automatic would be a lot nicer.

--
josh
       "Unix is very simple, but it takes a genius to understand the
		       simplicity." - Dennis Ritchie



Visit your host, monkey.org