[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Pseudo-cluster firewall



On Tue, 2004-11-02 at 19:55, Raffaele D'Elia wrote:
> Hi all,
> 
> I have a firewall with 3 NICs (LAN,DMZ,ROUTER); this is a single point of
> failure, of course! I've decided to build a backup firewall, with similar
> hardware (just in case) and the same config.
> Now the problem: I have only a cross-over cable from the router to the
> firewall, so I cannot connect the backup firewall.
<all the rest snipped>

The usual advice is *not* to connect two firewalls in parallel, lest
traffic that should not can get throught the other. You could keep the
other firewall as a spare that can be quickly applied if your current
one fails. (I use an known clean CD image in a similar fashion).

Sold state switches are pretty reliable these days but I can not get one
in a box for the middle of an ethernet cable, so you would have to make
one---the components are cheap but breadboard and scopes are not.



Reply to: