|
The reason why IPSO does not respond to network
connections that terminate
at a VRRP IP Address is because the implementation
of VRRP adheres to
RFC 2338.
As Scott McMeekin has noted, IPSO is evolving at a
fast rate and an RFE has
been submitted regarding this issue. Note only
would it be useful to be able to
query the virtual firewall in order to determine
which physical firewall is currently
the master, but the ability for IPSO to accept
network connections which terminate
at a VRRP IP address would support the use of the
Nokia Applications platform for
any other mission critical application for which HA
would be justifiable.
Given that a security enforcement perimeter
consists of firewalls, IDS', anti-virus
servers, etc... one would think that it is not only
the firewall for which we would want
a backup system.
I am looking forward to the next release of IPSO
which may include a Network Voyager
switch within the VRRP configuration page which
basically enables IPSO to accept
these connections.
Jerald Josephs
|
Title: RE: [FW1] Nokia failover
- [FW1] Nokia failover hermit1
- RE: [FW1] Nokia failover McMeekin, Scott
- RE: [FW1] Nokia failover Paul Keser
- RE: [FW1] Nokia failover McMeekin, Scott
- RE: [FW1] Nokia failover Rogue Bolo
- Re: [FW1] Nokia failover Rogue Bolo
- RE: [FW1] Nokia failover Bruce Cheng
- RE: [FW1] Nokia failover Paul Keser
- RE: [FW1] Nokia failover Rogue Bolo
- RE: [FW1] Nokia failover Paul Keser
- Jerald Josephs
