[nzlug] Hosting Direct firewalls

Anton anton.list at gmail.com
Wed Mar 14 22:35:01 NZDT 2007


On 14/03/07, Ben Simpson <ben at hostingdirect.co.nz> wrote:
> Hey guys, I am new to NZLUG.
> I run hosting direct nz's biggest free hosting company, we are making our
> network allot larger this week and I need some help sourcing some
> technologies to turn  2 Firewalls Linux Debian, 2 bandwidth ports each on
> separate feeding to a Cisco 2950 that falls over to each firewall and load
> balances with dynamic rule update, rate shaping down to the ip address level
> traffic and accounting and dual home support also we need some way to
> isolate individual server for other server on the same LAN/ip address range
> (I.e. dedicated server isolation)
> Anyone know any good web sites or anything?

As a Debian user myself, I would recommend OpenBSD for that purpose -
hopefully that wasn't too blasphemous for a first post :)

http://www.countersiege.com/doc/pfsync-carp/
http://www.openbsd.org/faq/pf/index.html
http://www.openbsd.org/faq/pf/queueing.html
http://www.openbsd.org/faq/pf/carp.html

If by some chances these firewalls are Xen guests instead of physical
boxes, you may still be able to run pf on NetBSD Xen guests.

-- 
Cheers
Anton



More information about the NZLUG mailing list