LARTC
[Top] [All Lists]

[LARTC] Re: gateway failover with linux

To: gtaylor+reply@riverviewtech.net
Subject: [LARTC] Re: gateway failover with linux
From: Abhijit Menon-Sen <ams@toroid.org>
Date: Sat, 21 Jul 2007 05:59:54 +0530
Cc: lartc@mailman.ds9a.nl
Delivered-to: sp-com-lists@consult.net
Delivered-to: lartc-list@securepoint.com
Delivered-to: lartc@outpost.ds9a.nl
In-reply-to: <46A0D0C1.4090805@riverviewtech.net>
List-archive: <http://mailman.ds9a.nl/pipermail/lartc>
List-help: <mailto:lartc-request@mailman.ds9a.nl?subject=help>
List-id: "Mailinglist of the Linux Advanced Routing &amp; Traffic Control project" <lartc.mailman.ds9a.nl>
List-post: <mailto:lartc@mailman.ds9a.nl>
List-subscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe>
List-unsubscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe>
References: <20070719170251.GA24923@toroid.org> <469FD455.9050903@riverviewtech.net> <20070720012032.GA29284@toroid.org> <46A0D0C1.4090805@riverviewtech.net>
Sender: lartc-bounces@mailman.ds9a.nl
At 2007-07-20 10:12:01 -0500, gtaylor@riverviewtech.net wrote:
>
> > I just want a hot standby for a single Linux firewall [...]
> 
> I would use a pair of Linux boxen with vrrpd and conntrackd

OK, great. I didn't know about vrrpd. I'll check it out.

> As far as ucarp, I'm not familiar with it so I can't comment.

If I have the time, I'll try out ucarp and post a summary of my
experiences for the archives.

> If you want to know what to do in this situation read about SONITH
> (Shoot Other Node In The Head) to make sure that there is only one
> active node at a time.

("STONITH", for those asking Google.)

I have one other question. How does conntrackd interact with traffic
shaping? My firewall also uses HTB to impose various bandwidth limits
on clients. From what I've read so far, I have the impression that the
failover may lose some packets that are being delayed in a queue, but
existing connections should recover and be esentially unaffected.

Can anyone confirm that?

-- ams
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

<Prev in Thread] Current Thread [Next in Thread>