Nokia's HA is VRRP (free), with a Monitored Circuit option (also free) to
cause any/all interfaces - you choose which ones - to fail over whenever
any one of them does. In my tests, it fails over in about 3 seconds, and
fails back in about 6 seconds - not long enough for anyone to really
notice. If you want load balancing, you need to look elsewhere. Load
sharing can be done with OSPF (also free).
The best part of Nokia is the way they handle upgrades of IPSO and
FW-1. You can switch between different versions just by clicking a button
and rebooting, so it is incredibly easy to back out when a problem is not
immediately resolvable. Not having to apply OS patches is good, too.
Neil
At 09:29 AM 7/6/00 -0700, John Loshbough wrote:
>I am currently running our Firewall (version 4.0) on a Solaris 2.6 box and
>am looking to upgrade the hardware and software. Shortly after the
>hardware is upgraded I'll have budget to add a high availability option.
>
>One of our people went to a Nokia sales presentation and said that we
>don't need to purchase the Checkpoint or other vendors high availability
>product because high availability comes with a Nokia box.
>
>Could someone knowledgeable about these issues help with the pros and cons
>of switching from Solaris to a Nokia box. Also I'd appreciate some
>comments about Nokia's (free) high availability vers Checkpoint's.
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================