Firewall Failover with pfsync and CARP

From: Daniel Hartmeier (daniel_at_benzedrine.cx)
Date: 03/30/04


Date: 30 Mar 2004 09:27:56 GMT

OpenBSD developer Ryan McBride <mcbride@openbsd.org> explains the new
firewall redundancy features in the upcoming OpenBSD 3.5 release[1]
in his article

  Firewall Failover with pfsync and CARP
  http://www.countersiege.com/doc/pfsync-carp/

CARP (Common Address Redundancy Protocol) is a free alternative to the
patent-encumbered VRRP, responsible for electing masters in a firewall
cluster, while pfsync syncronizes packet filter state information among
nodes.

The combination allows to replace single-point-of-failure firewalls with
clusters of two (or more) nodes, which continue to filter ongoing and new
connections when nodes fail. Additional features like arpbalance allow to
share a single IP address for multiple servers, transparently balancing
load among them, and adapting to servers failing.

Pre-order[2] for OpenBSD 3.5 has started, CDs will ship May 1st.

Daniel

[1] http://www.openbsd.org/35.html
[2] http://www.openbsd.org/orders.html



Relevant Pages

  • Re: Firewall Failover with pfsync and CARP
    ... we are using carp + pfsync + vlan in order to realize a cluster of firewall ... > Firewall Failover with pfsync and CARP ...
    (comp.unix.bsd.openbsd.misc)
  • Re: The Stunning Failure of OpenBSD
    ... To make the long story short, request your boss to spend about US$100 from ... his petty account to get any router + Firewall + NAT + QoS, ... to replace your Linux router. ... OpenBSD proved to be more ...
    (comp.os.linux.security)
  • Re: Internet Sharing - Security
    ... Can you recommend the steps that I would need to take once I have ... OpenBSD 3.0 installed on my system. ... >>>inexpensive Linux 2.4.x firewall with Netfilter and ISC DHCP is fine. ...
    (comp.security.firewalls)
  • Re: What firewall for small medical research lab
    ... There is no BEST firewall, if you will not use it at the right ... Then I found OpenBSD and stayed with it since. ... As far as cost, $45 for OpenBSD ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: Which Linux OS best for beginner to setup as Web / Mail server / Internet sharer and firewall?
    ... >>I don't want to start a flame war, but in my experience OpenBSD is best ... >>boxes if you must run linux for applications. ... > linux inside the firewall? ... web server? ...
    (comp.os.linux.networking)