Hello,

We have an OpenBSD firewall and we are planning to use CARP to add redundancy.
I have a question :
The firewall is a production firewall so we can't take it out of production for a long time.

I read somewhere that the following is possible :

Use the current IP address of the main firewall as the virtual IP address of the redundancy group ?

In this case all I need to do is to install new firewall and setup the pf rules and other interfaces and finally use the production firewall's IP address as the virtual one so to avoid losing connectivity

has anyone tried this before ?
Any notes or precautions ?

Thanks

--
Abbass MAROUNI
Internet Memory Foundation
internetmemory.org

  • CARP MAROUNI Abbass

Reply via email to