On Fri, 14 Apr 2006, octane indice wrote:
yes but in the first place, I will not use virtual server
Then, If that works, I want to add a DMZ
To become a thing like that:
.----FW backup---.
/ | \ \
INET--- | | +---LAN
\ | | /
`----FW master---'
\ |
\|
\
DMZ
On the firewall(s), VIP of the services. Real
servers in the DMZ.
so you want a firewall/director with failover using
carp/pfsync for the firewall functions and the server state
sync demon for ipvs services. But didn't you say that pfsync
isn't available for linux? Running a firewall on the
director with failover is a fairly normal operation now. It
doesn't use carp/pfsync.
Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!
|