Re: high availability and fiber channel



On 12 avr, 16:12, Arnold Nipper <arnold-200...@xxxxxxxxx> wrote:
On 12.04.2008 15:32 mikael.kermorgant.nos...@xxxxxxxxx wrote



Hello,

This is the current situation

------------> |||||||||||||||||| -----------------> Firewall
F.O. switch copper

I'd like to introduce high availability in this scheme by having 2
firewalls.

What would it take to avoid the SPOF keeping the switch introduces ?
Said differently, how could I "split" the optic fiber so that each
firewall would be plugged ?

The complete schema of my future setup is here :http://kgt.free.fr/objectif-net2.png

Just add a 2nd gateway to the internet. I.e.

/ The Internet \
| |
1st gw-----------2nd gw
|\ /|
| \ / |
| \ / |
| \ / |
| \ / |
| \ / |
| \ / |
| \/ |
| /\ |
| / \ |
| / \ |
1st firewall--2nd firewall

Arnold


Please forgive my ignorance but my question is just about technical
details as I don't know how to handle a fiber connection.
The trick now used is to put a switch with a SFP connector for this
fiber.

Given I replace the actual firewall with 2 new with SFP connectors,
I'd like to know if there's some passive way to mirror the incoming
traffic to the second firewall (which is sleeping, ready to takeover).
Or at least, what would the best way to handle this situation ? If
I'll have to keep that switch, I'll be able to sleep with it :)

Thanks,

Mikael
.



Relevant Pages

  • Re: hardware for fibre question ?
    ... firewall (Cisco PIX 535 with fiber card). ... For example if you put in a PIX firewall with a fiber card and the carrier ...
    (microsoft.public.windows.server.networking)
  • Re: [opensuse] Re: simple LAN
    ... He has fiber to his "office" where he has one ... Each "repeater" has it's own firewall. ... we were about 9 nano-seconds from the fiber [radio propagation speeds ... Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org ...
    (SuSE)
  • Re: [opensuse] Re: simple LAN
    ... It's a wireless ISP. ... He has fiber to his "office" where he has one ... Each "repeater" has it's own firewall. ... we were about 9 nano-seconds from the fiber [radio propagation speeds ...
    (SuSE)
  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)
  • Re: XP NOT RESPONDING
    ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.setup_deployment)