Multiple Firewalls with ipfilter?

Michael Richards michael at fastmail.ca
Wed Mar 26 21:03:20 PST 2003


We're supposed to provide redundant firewall service. I'm wondering 
if anyone has ever tried to do this and if it's realistic. Basically 
2 firewall machines hooked up so if one fails the other will 
transparently step in. I've googled it to death without much luck.

The security issue here lies in that the 2 firewalls can't talk to 
each other. So if I'm keeping state on a connection then the second 
firewall has to know about that connection otherwise it will close if 
that firewall dies.

Any ideas?

-Michael
_________________________________________________________________
    http://fastmail.ca/ - Fast Secure Web Email for Canadians


More information about the freebsd-security mailing list