NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] Re: Load Ballanced HA?




With Load balancing using virtual routers on each side of the firewall,
do the firewalls able to failover connections (no connection is reset during
failover?  If It can, how?

Thanks
Maureen A. Jacob
iBiz Solutions Consulting




-- Original Message --

>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>
>
>
>Carric Dooley
>Senior Consultant
>COM2:Interactive Media
>
>"But this one goes to eleven."
>- -- Nigel Tufnel
>
>
>On Wed, 24 Jan 2001 [email protected] wrote:
>
>> 
>> 
>> On Tue, 23 Jan 2001, Mark Squire wrote:
>> 
>> > Lets say I have two Nokia boxes and I want to:
>> > 1. Have them running in active-active-standby HA.
>> 
>> Nokia VRRP does not allow active-active only active-passive.
>
>Not entirely accurate.  While you cannot load balance with VRRP, you can
>"load share" by setting up two virtual routers on eachs side (one where
>firewall A is primary and firewall B is secondary, and the other where
>firewall B is primeary with firewall A as backup, and then split your
>network into two halves each using one of the VIP's for it's gateway.


>
>> 
>> 
>> > 2. VPN needs to be able to fail over.
>> 
>> With FW-1 4.1 this should work.
>> 
>> 
>> > 3. SecuRemote needs to be able to fail over.
>> 
>> Secureremote connects to the management station not the firewall. So
you
>> may need two.
>> 
>
>I have a document explaining how to setup redundant mgt consoles with NT,
>but it is extremely complex, and is more sort of a jury-rigged
>configuration. It involves several scripts that copy stuff from your
>primary to your backup console.  While I'm sure it works, and is quite
>ingenious, checkpoint does not provide and packaged solution to accomplish
>this.
>
>> 
>> > I have been digging and digging for the past couple of months for how
>to do
>> > this.  Does anyone either:
>> > 
>> > 1. Know how to do this?
>> 
>> Yes, you may need a second management station
>> 
>> 
>> > 2. Know where I can read how to do this?
>> 
>> I don't know where this would be documented.
>> 
>> Frank Keeney
>> Pasadena, CA
>> 
>> 
>> 
>> ================================================================================
>>      To unsubscribe from this mailing list, please see the instructions
>at
>>                http://www.checkpoint.com/services/mailing.html
>> ================================================================================
>> 
>
>-----BEGIN PGP SIGNATURE-----
>Version: PGP 6.5.1
>Comment: Made with pgp4pine 1.75-6
>
>iQA/AwUBOnBM4lUqWOkDpMZ2EQLM7ACfWJ7FOuJssdScomUOlFmYqnTc+tcAoJfP
>KWEA6jWX1y0qWA1uo8R+WQJ7
>=OqBG
>-----END PGP SIGNATURE-----
>
>
>
>
>================================================================================
>     To unsubscribe from this mailing list, please see the instructions
>at
>               http://www.checkpoint.com/services/mailing.html
>================================================================================
>






================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.