LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: ipvs and cluster firewall

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: ipvs and cluster firewall
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Fri, 14 Apr 2006 05:35:29 -0700 (PDT)
On Fri, 14 Apr 2006, octane indice wrote:

yes but in the first place, I will not use virtual server
Then, If that works, I want to add a DMZ
To become a thing like that:
       .----FW backup---.
      /        | \       \
INET---         |  |       +---LAN
      \        |  |      /
       `----FW master---'
                \ |
                 \|
                  \
                  DMZ

On the firewall(s), VIP of the services. Real
servers in the DMZ.
so you want a firewall/director with failover using 
carp/pfsync for the firewall functions and the server state 
sync demon for ipvs services. But didn't you say that pfsync 
isn't available for linux? Running a firewall on the 
director with failover is a fairly normal operation now. It 
doesn't use carp/pfsync.
Joe

--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml Homepage http://www.austintek.com/ It's GNU/Linux!




<Prev in Thread] Current Thread [Next in Thread>