netdev
[Top] [All Lists]

Re: shared-state firewalls/routers

To: Stuart Card <stu@xxxxxxxxxxxx>
Subject: Re: shared-state firewalls/routers
From: Lars Marowsky-Bree <lmb@xxxxxxxxxx>
Date: Mon, 28 Feb 2000 23:06:00 +0100
Cc: netdev@xxxxxxxxxxx
In-reply-to: <3.0.6.32.20000228170321.007d6790@mail.borg.com>; from "Stuart Card" on 2000-02-28T17:03:21
References: <20000228203956.C23998@pointer.teuto.de> <3.0.6.32.20000228170321.007d6790@mail.borg.com>
Sender: owner-netdev@xxxxxxxxxxx
On 2000-02-28T17:03:21,
   Stuart Card <stu@xxxxxxxxxxxx> said:

> There is a third method: have the standby router snoop what the active
> router did.

Only possible on none switched networks where both routers share the same
physical segment (or at least running "port mirroring" on the switch to make
both ports appear the same).

*considers*

This might even work quite easily. The simplest case may even be to configure
the switch to mirror both the inside and the outside ports of each box, and
toggle IP forwarding as the failover happens.

(Ignoring for once that now your switch is the SPOF, but that can probably be
taken care of by using two switches linked to eachother)

However, you'll need to resynchronise at least once after the failed system
restarts, because obviously it missed all the packets in between.

Sincerely,
    Lars Marowsky-Brée
        
--

<Prev in Thread] Current Thread [Next in Thread>