Security Basics mailing list archives

Re: firewall cluster


From: "Ivan ." <ivanhec () gmail com>
Date: Wed, 28 Mar 2007 09:04:50 +1000

Hi,

If you want a HA active/passive setup they must be the same firewall.

So either a Linux iptables firewall using linux HA
http://www.linux-ha.org/

or a OpenBSD/FreeBSD firewall
google it

cheers
Ivan

On 3/27/07, sandra <sandra () fib upc edu> wrote:
Hello,

We want to set up a cluster of two firewalls with heartbeat. It will be an active-passive
cluster, so if main firewall fails, secondary firewall would become active.
We think that, although they are a cluster, they should have different Operating Systems
(for example linux and BSD), so if a vulnerability has impact in our main firewall and
drops it, the second firewall will start to serve without the same vulnerability affecting it.
Do you think is a good idea or is better to have two identical firewalls for compatibility
issues?
Which combination of Operating Systems do you recommend?
Thanks,

Sandra




Current thread: