Great Circle Associates Firewalls
(January 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: re: Fault Tolerant Firewall
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Date: Tue, 23 Jan 1996 8:51:24 -0500 (EST)
To: firewalls @ greatcircle . com

Stefano rote:
>We are asked to warrant a >99,5% uptime for a firewall system in a financial
>organization. We're trying to figure out what's the best way to manage such 
>a problem (a fault-tolerant hardware solution?  A multiple firewall solution? 
>other tricky configurations?).
>Has anybody out there already experienced and solved such a problem?

Yes, but the answer can be expensive. One machine cannor guarentee this 
kind of uptime though RAID disks can help. Two machines can if all other
systems are also redundant (remember my story about the dump truck snapping
a power pole that landed on the backup generator building ?). Three are
better.

At the moment I do not know of any firewall using Tandem fail-operational
computers, so the first question is "will the site be manned at all times the
net is needed ?". If so you could use a manual switchover to a hot spare.
-All sessions in progress will experience interruptions but the net will
only be down for as long as it takes to switch the net.

I have been looking into multiple firewall machines from a performance 
standpoint (one for WWW, another for FTP, a third for other TCP) running
in parallel with the capabilitiy to reconfigure on failure but do not
know of anything commercial as yet.

>From my flight control days, I know that it takes three (minimum) to vote
intelligently to decide on "soft" failures though two can handle 
catastrophic. Dunno if anyone is working fail-op though most promise
fail-safe.

99.5% means about 3.5 hours downtime per month, not terribly hard to meet 
with a manual system and people on site. Depends on your needs.

						Warmly,
							Padgett

Indexed By Date Previous: Re: DNS Bind 4.9.3-BETA9 ..
From: Chris Woods <cjwoods @ paladin . com>
Next: Re: Firewalls-Digest V5 #51
From: mdr @ vodka . sse . att . com
Indexed By Thread Previous: Re: Fault Tolerant Firewall
From: mdr @ vodka . sse . att . com
Next: Re: Fault Tolerant Firewall
From: Dale Lancaster <dlancaster @ raptor . com>

Google
 
Search Internet Search www.greatcircle.com