Re: OpenBGP on firewall

2006-02-17 Thread Paolo Supino
Hi Henning Thanx for the reply :-) How do I make sure that the master is the one that advertises the routes to avoid asymmetric and packet loss? Since these FW systems will also act as a ISPEC peers (2 permanent and some couple of concurrent road warriors) what would you estimate be a good en

Re: OpenBGP on firewall

2006-02-17 Thread Henning Brauer
* Paolo Supino <[EMAIL PROTECTED]> [2006-02-16 19:54]: > I started working for a company that its production site is running 2 > PIX firewalls with no VRRP (to save cost on licensing, duh). I offered > and they approved to replace them with 2 OpenBSD and CARP. In front of > the FW there is a Ci

Re: OpenBGP on firewall

2006-02-16 Thread Reto Burkhalter
Hi I tried something similar: 2x machines (FreeBSD) with OpenBGPD, CARP (for fail-over of the internal default gateway), PF and pfsync. I encountered problems especially with assymetric routed traffic. E.g. traffic coming in via router 1, going to the client/server and going out via router 2. pf/

OpenBGP on firewall

2006-02-16 Thread Paolo Supino
Hi I started working for a company that its production site is running 2 PIX firewalls with no VRRP (to save cost on licensing, duh). I offered and they approved to replace them with 2 OpenBSD and CARP. In front of the FW there is a Cisco 7200 router doing BGP. I offered to remove the router