Hi,
We're in much the same position
internet
|
router
|
----------------
| |
b1 b2
| |
----------------
|
inside
b2's external interface is down by default. We use a 'floating ip'
for the firewall by using the 'alias' facility of Solaris. b2 will
monitor b1 and upon detecting failure, assume the identity of b1
both inside and out.
> - in case of firewall failure, fall back on router packet filtering
> without a firewall in place.
This leaves me cold. I should trash your firewall and then all I
have to worry about is getting through the router.
In my case, both dead and we're off the air.
Colin
References:
|
|