- 论坛徽章:
- 0
|
英文的,求翻译
Ipfwsync
Ipfwsync or 'Ipfw3sync' is the facility in ipfw3 which can synchronize firewall states between machines running ipfw3 firewall for high availability. It can be used together with CARP to make ensure a backup firewall has the same states as the main firewall. When the master machine in the firewall cluster dies, the slave machine will be able to takeover the service and accept current connections without loss. the firewall need to configured into ipfwsync "centre" and ipfwsync "edge". the centre will continuously sync the states to the edges using UDP protocol.
Use below commands to configure an ipfwsync edge. The edge will listen on the UDP port 5000.
ipfw3 sync edge 5000
ipfw3 sync start edge
Below command to configure an ipfwsync centre, and this ipfwsync centre will automatically sync the states to edge 192.168.1.1:5000 and edge 192.168.1.2:5001.
ipfw3 sync centre 192.168.1.1:5000,192.168.1.2:5001
ipfw3 sync start centre
Below command to verify whether the ipfw3 centre can send the test message to all the configured edges.
ipfw3 sync test centre 1 |
|