HA firewall with tinc

mlist mlist at apsystems.it
Wed Jan 27 02:31:46 CET 2016


I have 2 firewall in HA with keepalived. Can I use active the same tinc configuration on 2 firewalls ? using tun Interface with same ip on all 2 nodes is a problem ? tun device advertise itself on the network having an IP/MAC pairs (ARP) or the IP is only used by the system internally for routing so using the same configuration is right ? so one firewall be active, the other is passive. With this configuration I can avoid starting/stopping tinc with keepalived active passive node. Keepalived is sometimes problematic with Virtual Machine backup (snapshot stun time), transitioning from Master to Slave and vice versa at stun time, so we can avoid probability that keepalived will starting up and shutting down tinc erroneously.

Thank you


Roberto




-------------- parte successiva --------------
Un allegato HTML è stato rimosso...
URL: <http://www.tinc-vpn.org/pipermail/tinc/attachments/20160127/46ebf418/attachment-0001.html>


More information about the tinc mailing list