LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-21-2005, 05:58 AM   #1
Iptables_NEWBIE
LQ Newbie
 
Registered: Jul 2005
Location: sengkang
Posts: 10

Rep: Reputation: 0
Exclamation Iptables help!!!


Is there any iptables script with failover function.
we are having two desktop as firewall and we want to provide redundancy..
Any one to help???
 
Old 07-21-2005, 01:37 PM   #2
demian
Member
 
Registered: Apr 2001
Location: Bremen, Germany
Distribution: Debian
Posts: 303

Rep: Reputation: 30
If you have iptables configured as a stateful inspection firewall this is not so simple. You need to find a way to sync the connection tracking table of both (all) machines. This is what ct_sync is for. Furthermore you will need a way to detect when it's failover time. keepalived from the Linux Virtual Server Project is an option.

Out of the box solutions for this don't exist. I've used such a setup in a lab environment and it seems fine. However, the ct_sync code is still rather experimental and subject to change. So I wouldn't use it in a production environment yet.

*BSD has the ability to sync connection tracking tables for quite a while longer (using pfsync). For now this might be the safer option.
 
Old 07-21-2005, 05:48 PM   #3
tkedwards
Senior Member
 
Registered: Aug 2004
Location: Munich, Germany
Distribution: Opensuse 11.2
Posts: 1,549

Rep: Reputation: 52
At my company we replaced the main router for the network (an old cisco router) with 2 identical Linux machines. They use the heartbeat software (http://www.linux-ha.org/HeartbeatProgram) to work out if the other machine is still up. If one machine goes down the other will detect that (they are linked together by crossover ethernet cable and by serial cable) and will assume the role of primary machine.

The way it all works is that each machine has seperate IP addresses, in our case for eg. they appear on the LAN as 192.168.1.252 and 192.168.1.253. There is a 3rd heartbeat managed IP which belongs to whichever machine is primary at the moment. The third IP is 192.168.1.254 so we can just point machines on our LAN to that IP as the default gateway and it will be whatever machine is the primary machine for heartbeat at that time.
 
Old 07-21-2005, 11:03 PM   #4
Iptables_NEWBIE
LQ Newbie
 
Registered: Jul 2005
Location: sengkang
Posts: 10

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by tkedwards
At my company we replaced the main router for the network (an old cisco router) with 2 identical Linux machines. They use the heartbeat software (http://www.linux-ha.org/HeartbeatProgram) to work out if the other machine is still up. If one machine goes down the other will detect that (they are linked together by crossover ethernet cable and by serial cable) and will assume the role of primary machine.

The way it all works is that each machine has seperate IP addresses, in our case for eg. they appear on the LAN as 192.168.1.252 and 192.168.1.253. There is a 3rd heartbeat managed IP which belongs to whichever machine is primary at the moment. The third IP is 192.168.1.254 so we can just point machines on our LAN to that IP as the default gateway and it will be whatever machine is the primary machine for heartbeat at that time.
I have downloaded hearbeat before... But i'm having trouble configuring it... Can advise me how to configure it???

Thnx for ur help
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
An error occured getting IPtables status from the command /etc/rc.d/init.d/iptables s CrazyMAzeY Linux - Newbie 10 08-12-2010 05:25 AM
Iptables - Couldn't load target `ACCPET':/lib/iptables/libipt_ACCPET.so: z00t Linux - Security 3 01-26-2004 02:24 AM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 06:08 AM
iptables book wich one can you pll recomment to be an iptables expert? linuxownt Linux - General 2 06-26-2003 04:38 PM
My iptables script is /etc/sysconfig/iptables. How do i make this baby execute on boo ForumKid Linux - General 3 01-22-2002 07:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration