Michael, yes, I have layer2 between locations... And, yes, I want to keep it simple, but, need to prove that active/active is not a good way to go to my manager -- Att... Ricardo Felipe Klein klein.rfk@xxxxxxxxx On Wed, Nov 5, 2014 at 5:57 PM, Michael Schwartzkopff <ms@xxxxxxx> wrote: > Am Mittwoch, 5. November 2014, 17:50:05 schrieb Ricardo Klein: >> Michael, >> >> thanks for your repply, I forgot to mention that each one are in >> different places, so I wanted to set each local network to use the >> nearest firewall. And yes, I will have a hardware that can handle the >> whole network. > > Do you have a layer 2 connection between both locations? Or do you do some > dynamic routing changes in the case of a failover? > >> But, why not active/active? (sorry for the silly question, if you can >> just point me to any good source I can read about, its ok, no need to >> waste your time with this) > > Source: Common sense. > > A load-balancing firewall makes things complicated. Keep it simple, so it will > work reliable. > > > Mit freundlichen Grüßen, > > Michael Schwartzkopff > > -- > [*] sys4 AG > > http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044 > Franziskanerstraße 15, 81669 München > > Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 > Vorstand: Patrick Ben Koetter, Marc Schiffbauer > Aufsichtsratsvorsitzender: Florian Kirstein -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html