Great Circle Associates Firewalls
(March 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: FW-1 redundancy
From: "Jose R. Ferreira" <jricardo @ medidata . com . br>
Date: Mon, 30 Mar 1998 14:35:10 -0300
To: Firewalls @ GreatCircle . COM



From: Jose R. Ferreira @
 MLX on 30/03/98 14:35


Hi All,

I am looking for a solution to give more availability to an Internet site.
Today its configuration is quite simple:


               External router
                   |
            _______|___________
                   |
                 FW-1 (Checkpoint)   + NAT
                   |
             ______|___________
                   |
            Internal network



I am thinking about in the diagram below, using a routing protocol like
OSPF or RIP to inform internal network that there is another route if a
FireWall or a link fails, using a internal router as a default gateway for
the internal network.


                External router
                          |
             _____________|_____________
                   |               |
                   |               |
                 FW-1 2.0        FW-1 2.0
                   | (NAT)         | (NAT)
             ______|_______________|____
                          |
                    Internal router
                      |
                      |
               Internal Network


Does anyboby know if the FireWall-1 product supports synchronization
(the state tables and rules are kept in synchronization) ?


I have read about a solution from stonesoft, called stonebeat. Does anybody
have some experience with this product ?

I am very interested to know your opinion, experience and solutions for
this situation.

Regards,
Jose Ricardo




Follow-Ups:
Indexed By Date Previous: Re: Ammunition, please
From: Jack Danahy <jdanahy @ bbn . com>
Next: Re: Ammunition, please
From: "Ryan Russell" <ryanr @ sybase . com>
Indexed By Thread Previous: Re: RAPTOR performance
From: Clyde Williamson <dclydew @ interhack . net>
Next: Re: FW-1 redundancy
From: Nobuhiko Yoshimoto <yoshi @ koto . nikkei . co . jp>

Google
 
Search Internet Search www.greatcircle.com