Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Redundant FW-1's
From: Justin Mason <jmason @ iona . com>
Date: Tue, 26 Nov 1996 11:43:04 +0000
To: Russ <Russ . Cooper @ rc . on . ca>
Cc: "firewalls @ greatcircle . com" <firewalls @ greatcircle . com>
In-reply-to: <F19A117D9446D011A0830000E8D5C667000000002F51 @ mail . rc . on . ca>

Russ said:

>First of all, Integrix themselves don't even make that claim for their 
>HA1000, they simply refer to the reality that their HA system provides 
>complete HARDWARE fault tolerance. Hot swappable devices and dual 
>motherboards does not "eliminate the "single point of failure" issue". 
>If you want to eliminate a single point of failure, you have to go 
>beyond the hardware to software as well.

[drifting a little from the firewalls charter ;]

Yeah, this is a pet hate of mine as well. There's nothing more
pointless than a really nice highly-available hardware setup, with
buggy kernel-level software installed which crashes it on a regular
basis (a particular version-control system comes to mind).

ObFirewalls:

Re: Phrack issue 49 article 07, Project Hades' "Vengeance", which
crashes inetd by sending a SYN followed immediately by a RST.  I
haven't seen any discussion or patches for this, although the article
states that it's easy enough to patch. Rather than build the tools and
do the work myself, I'm hoping someone's already done this ;)

--j.



References:
Indexed By Date Previous: Remote Access to Corporate LAN
From: Mahesh Ravji <Mahesh . Ravji @ wang . co . nz>
Next: PIX vs Others
From: "Adrian Gustavo Russo" <arusso @ caro . buenosaires . sgi . com>
Indexed By Thread Previous: RE: Redundant FW-1's
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Ramifications of denying all incoming UD
From: SOBRIEN @ MAIL . STATE . WI . US

Google
 
Search Internet Search www.greatcircle.com