LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-20-2011, 06:40 AM   #1
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Rep: Reputation: 32
Central default GW with firewalling


Hello!

We have a big company network and i am planing to set up a new default gateway ( ha ).

So my question:

Has anybody already such a system and how would that look like.

Actually I plan with SLES11 64bit DL380G6 cluster with bonding 8 nic`s with each 1Gbit uplink.

Any suggestions ?
How would i make it HA ? ( just googling HA cluster SLES...)

Thanks for any idea !
 
Old 09-20-2011, 11:42 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,623

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
HA Gateway

Personally, I went with ASTARO instead of rolling my own.

They pretty much automate or simplify everything I wanted to do in a firewall.

And it is open-source, so you can download and run without a license if you must. (Though that means running without support, security patches, etc.)
 
Old 09-20-2011, 03:21 PM   #3
saavik
Member
 
Registered: Nov 2001
Location: NRW, Germany
Distribution: SLES / FC/ OES / CentOS
Posts: 614

Original Poster
Rep: Reputation: 32
I have no problem with missing updates but i need more than 300 connectikns at a time.

ip-conntrack !

would that work with the open-sorce version of astaro?

I can only find a personel version not an open source version.

Do you have a link ?
Can you make a cluster of it?
 
Old 09-21-2011, 10:24 AM   #4
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,623

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
Astaro

I have not tried the ASTARO personal version: we use licensed ASTARO security appliances at work.

I have one with over 60 VPN connections alone, some of them with as many as 30 class C subnets per VPN. That is a LOT of traffic, and we have never had a problem.

We also run the PPTP VPN configuration, just for Network and System Administrators.

We did have two configured in a HA failover cluster (there is a how-to on the ASTARO web site: they make it easy) but we have broken that cluster to use the second for our Disaster Recovery site now.

I am not aware of any restrictions on the personal edition that would restrict this kind of usage, but (as I said) I have not tried.

If you must go the FREE and unsupported route, there are some gateway appliance Linux distributions out there worth looking into. Have you checked in DISTROWATCH for ideas?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewalling Problem Palula Linux - Networking 2 05-03-2006 10:36 PM
Firewalling My Home Network ferdog Linux - Networking 2 05-30-2004 11:37 PM
firewalling questions Ninja_212 Slackware 4 11-10-2003 03:26 PM
Slackware firewalling jamaso Linux - Security 1 02-08-2002 10:33 AM
Kernel 2.4.* and firewalling projfw Linux - Newbie 3 08-01-2001 07:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration