carp + pfsync + pf



List,

Hi! Good day, my first post to this lists, was unreadable due to or
possibly a yahoo bug, well here it goes, i have been task to setup a
redundant firewall. Setting up carp + pfsync was a breeze even though
carpdev option was not present as of this time to freebsd.

My preliminary test shows that through simulation (yanking the cable
and so on), the secondary firewall successfully takeover the primary
and the firewall state is sync via crossover cable on both machine.

pfctl -s s show both machine have a common state but the problem is
the connection dies unexpectedly on the client side during simulation.


note: On OpenBSD the same setup and configuration is made and its
working perfectly without a hitch though it's a different machine.

can someone please shed some light about this? Thanks in adavnce to all

Best regards,

Ronald Chan
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: How to get rid of persistent virus programs.
    ... > Long query about dealing with Pesky trojans and spyware ... > At least something like before and after lists, ... I'll mainly work around Windows XP, as that is what the bulk of this ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.help_and_support)
  • [fw-wiz] Re: Best Practices
    ... people separate network level (firewall, proxy, router acls, etc.) from ... so a security policy might be a base best practice;> Only part ... best practices aren't as much about giving people specific lists ... practices, I know I have other things to do and I assume you and Paul do ...
    (Firewall-Wizards)
  • RE: Looking for ipfw info.
    ... > legacy stateless rules when only stateful rules should be used to ... Yes for an firewall without an lan behind it ... You can access this lists archives at ... Then search the questions list archives at ...
    (freebsd-questions)
  • Spyware Blocklist 12/22/2002
    ... Entries for spyware which are new will say so. ... Changed references to the old Tiny Personal Firewall to the newer ... In the Network Mask box, enter the number from the middle ... might be able to delete rules in the previous lists which block ...
    (comp.security.firewalls)
  • RE: Defense plan
    ... IAS to let users authenicate when they connect to the Internet. ... Internet Firewall set to deny all except for allowed traffic ... Set chkrootkit to run with a cron job on Linux boxes. ... Encrypt sensitive documents like lists of passwords, machine names, or ...
    (Security-Basics)