* Eugene Yunak <e.yu...@gmail.com> [2010-03-07 17:58]:
> Time for the "bgpdsync" (as in pfsync)? Sounds like a nice idea to me.

please. think it through. it's not like we would not like that.

you had to:
-have a way to migrate the tcp session with all its state over
this is actually the hard part. a tcp session creates a bit of state,
and pushing that down to the stack on the backup is not possible as of
now.

-have the ipsec layer synced for md5 keys or keys for real ipsec
 (isakmpd setups, anyone?)

-have the two bgpds sync their state wrt the affected session

diffs welcome. hrhr.

-- 
Henning Brauer, h...@bsws.de, henn...@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting

Reply via email to