RE: Using heartbeat for fall over on IPTables Firewall

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le lun 17/03/2003 à 23:08, Steve Mickeler a écrit :
> Just off the top of my head:
> 1) heartbeat is limited to 2 nodes
> 2) keepalived config is much cleaner and easier to manage.

Moreover, keepalived supports VRRP, which means it can interoperate with
other devices that support this protocole and is far more flexible in
terms of configuration. It also supports IPSEC-AH authentication, as
defined in VRRPv2.

VRRP has been defined to provide flexible failover for routers, and is
so applicable to packet filters. In this usage, it is to my mind much
efficient than heartbeat.

-- 
Cédric Blancher  <blancher@xxxxxxxxxxxxxxxxxx>
IT systems and networks security expert  - Cartel Sécurité
Phone : +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99
PGP KeyID:157E98EE  FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux