Kjetil Torgrim Homme wrote:
> > Has anyone attempted/is currently running LVS as a pair of
> > fault-tolerant firewalls?
> (Julian Anastasov is working on making LVS integrate with Netfilter.
> LVS passes on the packets before firewall rules are applied. if the
> code is completed, Netfilter integration will be an option since the
> performance penalty is quite noticable.)
Currently running a firewall doesn't fit well with being a director.
http://www.linuxvirtualserver.org/Joseph.Mack/HOWTO/LVS-HOWTO.patches.html#firewall_on_director
However as Kjetil says, I will be an option sometime.
There are people who believe that firewalls should be modular and not
run on machines doing other jobs
Joe
--
Joseph Mack PhD, High Performance Computing & Scientific Visualization
SAIC, Supporting the EPA Research Triangle Park, NC 919-541-0007
Federal Contact - John B. Smith 919-541-1087 - smith.johnb@xxxxxxx
|