login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
openbsd-misc
»
2008
»
August
»
25
Re: bridge and carp
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [thread] [
date
] [
author
]
[view in full thread]
From: Marco Fretz
Subject:
Re: bridge and carp
Date: Monday, August 25, 2008 - 5:45 am
alexander lind wrote:
quoted text
> On Aug 20, 2008, at 12:06 AM, Marco Fretz wrote: > >>> Is it possible to have two OpenBSD bridging firewalls work together >>> with CARP now? >> >> What do you mean by "work together"? Only fail-over? load-share? > > Fail-over is my primary concern. > >>> >>> Update the ifp of bridge cache entries if the entry is not static. >>> This makes carp(4) fail-over work over bridge(4). >> >> I think this means only that it is possible to use carp over bridges, >> not for bridges. but maybe I'm wrong. :-) > > Ah, that makes sense I suppose since I can't find many references to > this particular scenario elsewhere! > >>> So my question is, am I understanding this right if I say that it is >>> indeed possible to set up a pair of redundant carped firewalls using >>> OpenBSD 4.2 or above? >> >> Bridges are layer 2, carp is layer 3 (it shares IP addresses). So carp >> can not handle this by its nature I think. Just place the both bridges >> in your LAN and you have your fail-over solution. I've never done >> something with openbsd bridges but as I know it from bridge-utils from >> linux you can set STP priority and costs to influence spanning tree path >> selection. Of course your LAN switch should be capable of basic >> spanning-tree functions as well. >> >> after the first bridge goes down, spanning tree takes automatically the >> next best path by setting the needed switchports to forward (instead of >> blocking). > > This sounds like the best route for us. I will experiment and see if I > can get it working like this later today. > > Thanks for your advice!
Your welcome. Let me know if it's working or not. I've never done it myself but I'm also interested in bridging firewall clusters... bests marco
quoted text
> > Alec
Previous message: [
thread
] [
date
] [
author
]
Next message: [thread] [
date
] [
author
]
Messages in current thread:
bridge and carp
, alexander lind
, (Tue Aug 19, 6:11 pm)
Re: bridge and carp
, alexander lind
, (Tue Aug 19, 7:10 pm)
Re: bridge and carp
, Marco Fretz
, (Wed Aug 20, 12:06 am)
Re: bridge and carp
, Harald Dunkel
, (Wed Aug 20, 12:36 am)
Re: bridge and carp
, Henning Brauer
, (Wed Aug 20, 5:02 am)
Re: bridge and carp
, Harald Dunkel
, (Wed Aug 20, 7:30 am)
Re: bridge and carp
, Paul de Weerd
, (Wed Aug 20, 8:24 am)
Re: bridge and carp
, alexander lind
, (Wed Aug 20, 3:22 pm)
Re: bridge and carp
, Marco Fretz
, (Mon Aug 25, 5:45 am)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Trenton D. Adams
Re: Flash IO slow 1.5 MB/s
Alan Cox
Re: Please add ZFS support (from GPL sources)
S K
Re: cpufreq doesn't seem to work in Intel Q9300
Bart Van Assche
Re: Is gcc thread-unsafe?
Con Kolivas
Re: [PATCH][RSDL-mm 0/7] RSDL cpu scheduler for 2.6.21-rc3-mm2
git
:
Junio C Hamano
Re: git-svnimport
Johannes Schindelin
Re: [PATCH] Fix approxidate("never") to always return 0
A Large Angry SCM
Re: [RFC] origin link for cherry-pick and revert
Junio C Hamano
Re: [PATCH] Detached HEAD (experimental)
Mark Burton
Re: Sporadic BSOD with msys git?
git-commits-head
:
Linux Kernel Mailing List
ath9k_htc: Allocate URBs properly
Linux Kernel Mailing List
sm501: add power control callback
Linux Kernel Mailing List
powerpc/kexec: Add support for FSL-BookE
Linux Kernel Mailing List
V4L/DVB (8976): af9015: Add USB ID for AVerMedia A309
Linux Kernel Mailing List
ARM: 5670/1: bcmring: add default configuration for bcmring arch
linux-netdev
:
Daniel Lezcano
getsockopt(TCP_DEFER_ACCEPT) value change
David Miller
Re: 2.6.27.18: bnx2/tg3: BUG: "scheduling while atomic" trying to ifenslave a seco...
Ingo Molnar
Re: [regression] nf_iterate(), BUG: unable to handle kernel NULL pointer dereference
Jeff Kirsher
[net-2.6 PATCH 2/5] e1000e: increase swflag acquisition timeout for ICHx/PCH
Gerrit Renker
[PATCH 37/37] dccp: Debugging functions for feature negotiation
openbsd-misc
:
daniele.pilenga
snmpd hangs on 4.1 looking up hrSWRunTable
Christophe Rioux
Implementation example of snmp
Nick Holland
Re: booting openbsd on eee without cd-rom
Bryan Irvine
Re: OpenBSD 4.7 Released, May 19 2010
Cabillot Julien
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA
Colocation donated by:
Syndicate