Re: Linux Firewall Active/Active

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I asked about update the documentation before and no one responded. I
was perfectly willing to do it I just didn't know the procedures.
I know its on the todo list and has been for quiet some time. I was
stunned that no one replied to my inquiry.


On Wed, Nov 5, 2014 at 6:55 PM, Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> On Wed, Nov 05, 2014 at 05:43:39PM -0500, Paul Robert Marino wrote:
>> I've actually been doing this successfully with conntrakd, keepalived,
>> and quagga
>>
>> Essentially I'm using quaga for OSPF and BGP externally with equal cost paths.
>>
>> For conntrackd with FTFW and "DisableExternalCache On"
>>
>> Do NOT use the howto's on the web or the examples that come with
>> conntrakd or keepalived for configuring keepalived they are outdated
>> and can cause major problems.
>
> It would be great if you can contribute a patch to extend the
> conntrack-tools manual to document this. The documentation is
> available in docbook format in the git tree. People asks for this
> configuration on the mailing list from time to time.
>
> Thanks.
>
> P.S: I think that update should also indicate that possible race
> conditions may happen between the synchronization and packets in
> active/active asymmetric path, so people are aware of it too.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux