由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
EmergingNetworking版 - Internet Multi Sites Firewall Failover
相关主题
facebook电面。。。只能用惨烈来形容switch vs hub
facebook 面试攻略intern面试,求经验
RHEL怎么配置floating IP问一个ASA的问题。
是不是这个意思?问几个ASA的问题,不要见笑。
很久没来了,贡献一个面经吧。有什么ASA快速入门的材料推荐一下的么?
entry level面经40/100G Throughput Firewall
有关 ASA IPS 的问题Site-to-Site VPN 路由器的配置是必须的是吧?
新手工作总结和讨论,请大家多给意见!!!How to connect a 7900 to remote call manager ?
相关话题的讨论汇总
话题: failover话题: firewall话题: sites话题: asa话题: fwsm
进入EmergingNetworking版参与讨论
1 (共1页)
a***n
发帖数: 262
1
I am always curious about how big service provider
do this.
Take an example, I have two sites, running BGP with
one service provider at each location. How do you
implement the firewall failover at these two locations?
For Cisco ASA or FWSM, my understanding is that you
have to run ASA/FWSM in transparent mode, and put them
in a failover pair which means these two sites has to
be in HSRP/VRRP for the pass thru VLANs.
Another mode I used in our campus, just stateless
symmetric routing failover. Each ASA/FWSM is standalong except
they have the same firewall rules. No state information
changed and no HSRP/VRRP.
Could Juniper ScreenOS/SRX have better approach?
I would like to have the dynamic routing flexibility with state
information in sync, but do not want these two devices to
use HSRP/VRRP.
z**r
发帖数: 17771
2
don't quite understand your question. you want failover within the site or
you want failover cross the sites?
btw, you don't have run the firewall in transparent mode, coz BGP is TCP
based, as long as the 2 BGP routers can reach each other via TCP, then they
are good to go

【在 a***n 的大作中提到】
: I am always curious about how big service provider
: do this.
: Take an example, I have two sites, running BGP with
: one service provider at each location. How do you
: implement the firewall failover at these two locations?
: For Cisco ASA or FWSM, my understanding is that you
: have to run ASA/FWSM in transparent mode, and put them
: in a failover pair which means these two sites has to
: be in HSRP/VRRP for the pass thru VLANs.
: Another mode I used in our campus, just stateless

m********d
发帖数: 188
3
还是那个问题,是在说SP网络呢,还是corp IT网络?
firewall failover cross two remote sites?HA可能比firewall本身的
硬件更不可靠吧?
a***n
发帖数: 262
4
Corp IT, but two sites with distance.
Yes, firewall failover cross two remote sites.

【在 m********d 的大作中提到】
: 还是那个问题,是在说SP网络呢,还是corp IT网络?
: firewall failover cross two remote sites?HA可能比firewall本身的
: 硬件更不可靠吧?

a***n
发帖数: 262
5
Failover cross the sites.
Yes, I am aware of that. It looks like Cisco people
usually don't think no dynamic routing support
in ASA/FWSM context mode is not a big issue :-)

they

【在 z**r 的大作中提到】
: don't quite understand your question. you want failover within the site or
: you want failover cross the sites?
: btw, you don't have run the firewall in transparent mode, coz BGP is TCP
: based, as long as the 2 BGP routers can reach each other via TCP, then they
: are good to go

m********d
发帖数: 188
6
firewall failover across multiple sites, 我能想到的问题有两个:
1,ha会不会比硬件本身更不可靠
2,firewall failover和routing不配合怎么办?
至于整体网络结构有多“创新”,倒不是最重要的了,喜欢就行,呵呵。
1 (共1页)
进入EmergingNetworking版参与讨论
相关主题
How to connect a 7900 to remote call manager ?很久没来了,贡献一个面经吧。
VPN 代理服务器entry level面经
IPv6 RA and FHRP有关 ASA IPS 的问题
juniper的access layer的redundancy有什么feature?新手工作总结和讨论,请大家多给意见!!!
facebook电面。。。只能用惨烈来形容switch vs hub
facebook 面试攻略intern面试,求经验
RHEL怎么配置floating IP问一个ASA的问题。
是不是这个意思?问几个ASA的问题,不要见笑。
相关话题的讨论汇总
话题: failover话题: firewall话题: sites话题: asa话题: fwsm