External CARP + SSL issues

2010-03-01 Thread Extra Fu
Hello everybody, I need help regarding the following situation. I have four OpenBSD firewalls configured to do load-balancing ( in and out) using ip-stealth. I have two CARP interfaces (internal and external) on each firewall. See the configuration below. Load-balancing works perfectly for non-SS

External CARP + SSL issues

2010-03-25 Thread Extra Fu
Hello everybody, I'm reposting this message as I got no answer on this email in the past few weeks. Maybe someone has insights on what could be wrong. I need help regarding the following situation. I have four OpenBSD firewalls configured to do load-balancing ( in and out) using ip-stealth. I hav

Re: External CARP + SSL issues

2010-03-26 Thread Extra Fu
Hello, > Where is the web server? > Is it internal or is it an external web server? It was all `external servers. > What does telnet web_server 443 and > openssl s_client -connect web_server:443 > gives you? > > Have you tried sniffing the traffic to see what goes wrong? I can't test right now

CARP + ip-stealth > going through the same server

2009-12-09 Thread Extra Fu
Hello, I'm currently using 4 active-active OpenBSD 4.4 servers as a fully redundant firewall. CARP has been configured on the internal interfaces to expose the load-balanced IP address using ip-stealth on the four carpnodes. Each OpenBSD server has a different external IP address and I've recentl