Really cool article about failover firewalls with several OpenBSD utilities, CARP and pfsync. I am not very familiar with OpenBSD but the CARP portion of this technique sounds a bit similar to Linux-HA using Heartbeat. Basically CARP (Common Address Redundancy Protocol) allows a virtual MAC address and one or more virtual IP addresses, which hosts "share". If a primary host fails a secondary takes over. Very cool. The really interesting part is however pfsync. This is a utility to sync firewall state: "transfers state insertion, update, and deletion messages between firewalls. Each firewall sends these messages out via multicast on a specified interface, using the PFSYNC protocol". Combined you have failover firewalls.
For more see the linked article by Ryan McBride. Firewall Failover with pfsync and CARP
Chatter
2 days 18 hours ago
2 days 20 hours ago
4 days 21 hours ago
1 week 1 day ago
2 weeks 15 hours ago
2 weeks 6 days ago
2 weeks 6 days ago
3 weeks 4 days ago
4 weeks 16 hours ago
4 weeks 1 day ago