FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Firewall bake-off?

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.cybertrust.com>
Subject: Re: [fw-wiz] Firewall bake-off?
From: "Patrick M. Hausen" <hausen@punkt.de>
Date: Wed, 21 Mar 2007 22:51:02 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <90b025640703210959k245f42e7tcbf3a0cffaec6eae@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <948caa7e0703121637sa283960n552ec4e14900666f@mail.gmail.com> <1CE69584EC644F40B2D9B69003C56AD91F9D025B1B@carbon.japrinting.com> <dc718edc0703181946r2052f437v5afe6d84fc8417f7@mail.gmail.com> <4600554A.9060403@gmail.com> <90b025640703210959k245f42e7tcbf3a0cffaec6eae@mail.gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Mutt/1.5.10i
Hi, all!

On Wed, Mar 21, 2007 at 09:59:03AM -0700, Jim MacLeod wrote:
> On 3/20/07, Zachary Grafton <chaotic.chowder@gmail.com> wrote:
> > Well, the greatest thing about the sidewinder is how easy it is to
> > configure things. It does have clustering and nice failover features,
> > which are in my opinion, extremely important. If you are worried about
> > performance with a Sidewinder, just buy another one and cluster them.
> 
> Does it support active-active load splitting?  Or do you need an
> external load balancer for that?  How destructive is the transition
> when one fails?  How extensive is the state sync?  Will it scale to
> n+1, or is it limited to 2 firewalls?

Active-active with 2 units. Needs external load balancer for N > 2.
But facilitates policy configuration by "one-to-many" cluster mode,
i.e. you configure policy once for N firewalls.

Beware: active-active uses layer 2 multicast - which may be an issue if
your Internet uplink, is, say, 34 M and you have servers directly behind
or in front of the firewall on a 100 Mbit/s LAN. Your switches will
broadcast all traffic to the firewalls to all ports in the same collision
domain. Layer 3 separation of DMZ LANs recommended.

Regards,
Patrick M. Hausen
-- 
punkt.de GmbH * Vorholzstr. 25 * 76137 Karlsruhe
Tel. 0721 9109 0 * Fax 0721 9109 100
info@punkt.de       http://www.punkt.de
Gf: Jürgen Egeling      AG Mannheim 108285
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>