Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall high availability Strategy
From: Adam Shostack <adam @ homeport . org>
Date: Mon, 17 Mar 1997 07:51:58 -0500 (EST)
To: richards @ netrex . com (Richard Stiennon)
Cc: david @ ilanet . slnsw . gov . au, Firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 1 . 32 . 19970316210424 . 008eb480 @ anton . netrex . com> from Richard Stiennon at "Mar 16, 97 09:04:24 pm"

Richard Stiennon wrote:
| At 11:38 AM 3/17/97 +1100, David Cragg wrote:

| Level 3.  Stonebeat keep alive software with dual FireWall-1 installations
| in parallel. The Stonebeat element monitors primary FW from secondary. If
| it detects outage it renumbers ports on secondary to be same as old primary
| (IP address *and* MAC address).  The advantage is that the network does not
| have to learn new routes. Convergance time we have tested to less than 5
| seconds. With FW-1 3.0 state is maintained across both firewalls. An
| authenticated session sees only a five second delay. You *do not* have to
| re-authenticate.

http://www.stonebeat.com/sb-wp.html#How StoneBeatTM writes:

>Simple TCP connections like telnet, http, smtp etc. won't event
>disconnect while the switch over. More sophisticated connections, like
>FTP and RPC, where the firewall module contains more state information
>of the connections needs to be re-established after the switch over.
>(See FireWall-1TM v3.0 Connection Control option which may be used to
>avoid this.)

Sounds like they're using ACK bits in the first level of fail over.
The last time I looked for details on "Connection Control's"
authentication and integrity mechanisms, no useful info was available.
I'm sure someone will point out if this has changed.

Adam


-- 
"Well, that depends.  Do you mind the end of civilization as we know
it?"






References:
Indexed By Date Previous: NT Information
From: "Sandra Jaque F." <sjaque @ arauco . reuna . cl>
Next: RE: Imap
From: "Clara Lourdes Rodriguez" <LOURDES @ hermes . icmf . inf . cu>
Indexed By Thread Previous: Re: Firewall high availability Strategy
From: Richard Stiennon <richards @ netrex . com>
Next: Re: Firewall high availability Strategy
From: Roger Young <youngr @ erinet . com>

Google
 
Search Internet Search www.greatcircle.com