Re: OSPFd, CARP and pfsync

2006-10-12 Thread Ronnie Garcia
Claudio Jeker a icrit : On Tue, Oct 10, 2006 at 07:59:23PM +0200, Ronnie Garcia wrote: I have an OSPF enabled backbone and want to insert two firewalls. Each firewall will be connected to one different core router. My idea is to setup OSPFd on the interfaces plugged to the core, and CARP on th

Re: OSPFd, CARP and pfsync

2006-10-11 Thread Andreas Östling
On Tuesday 10 October 2006 19:59, Ronnie Garcia wrote: > I have an OSPF enabled backbone and want to insert two firewalls. > Each firewall will be connected to one different core router. ... > With this design, a SYN packet can enter thru FW2 and the > corresponding ACK packet go back thru FW1. > >

Re: OSPFd, CARP and pfsync

2006-10-11 Thread Henning Brauer
* Chris Cappuccio <[EMAIL PROTECTED]> [2006-10-10 20:56]: > Ronnie Garcia [EMAIL PROTECTED] wrote: > > > > Will pfsync just handle the split sessions happily ? Will it handle the > > load for, say, 10k pps ? > > > > with a soekris net4501? no > > with a 500mhz celeron or higher? yes uh, caref

Re: OSPFd, CARP and pfsync

2006-10-11 Thread Claudio Jeker
On Tue, Oct 10, 2006 at 07:59:23PM +0200, Ronnie Garcia wrote: > Hello, > > I have an OSPF enabled backbone and want to insert two firewalls. > Each firewall will be connected to one different core router. > > My idea is to setup OSPFd on the interfaces plugged to the core, and > CARP on the int

Re: OSPFd, CARP and pfsync

2006-10-10 Thread Chris Cappuccio
Ronnie Garcia [EMAIL PROTECTED] wrote: > > Will pfsync just handle the split sessions happily ? Will it handle the > load for, say, 10k pps ? > with a soekris net4501? no with a 500mhz celeron or higher? yes -- "Do you even send e-mails?" "I told you, I'm from the Wild West. I write by hand.

OSPFd, CARP and pfsync

2006-10-10 Thread Ronnie Garcia
Hello, I have an OSPF enabled backbone and want to insert two firewalls. Each firewall will be connected to one different core router. My idea is to setup OSPFd on the interfaces plugged to the core, and CARP on the interfaces plugged to the other side (servers network). I have no routing prot