[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1772.0. "disaster recovery for UNIX firewall" by SNOFS1::NANCARROW () Wed Feb 05 1997 01:15

    Our site is considering Disaster recovery for our firewall box.
    One possibility is having a cold standby box with a dump of the
    firewall partitions on it. Is this possible ?
    
    does the firewall retain a record of the ethernet addresses used
    or any CPU information or disk size information etc which would
    prevent this.
    
    We are also considering running either parallel firewalls or clustered
    firewalls is either of these possible.
    
    						Mike N.
T.RTitleUserPersonal
Name
DateLines
1772.1additionalSNOFS1::NANCARROWWed Feb 05 1997 01:174
    Also if we did this and used a different CPU and memory would we have
    any issues from reconfiguring the kernel on a firewall box.
    
    						Mike N.
1772.2QUICHE::PITTAlph a ha is better than no VAX!Wed Feb 05 1997 08:577
    Use RAID hardware to address disk failure, and identical redundant
    hardware for the CPU and memory.
    
    Don't use a different CPu and memory, or yes, you'll have to do a
    kernel rebuild ...
    
    T
1772.3ase - it's beeb done beforeSNOFS1::stylia.sno.dec.com::snov14::stylianouaWed Feb 05 1997 18:415
I'll be speaking with Kevin Carey re: how to do
an ase install with the AFWU. I'll let you all know
when it is available.

AS
1772.4risk managementSNOFS1::NANCARROWFri Feb 07 1997 00:1513
    But will the firewall work on a non-identical system with a
    reconstructed kernel. The reason being that until I have a solution
    where I can suggest to the customer either a parallel firewall setup
    or a clustered firewall setup I have the possibility of suggesting
    the use of a non-identical box which can be used as an identical
    twin, but non-active, to another system.
    This could be seen as acceptable risk management to the customer
    where I have two highly reliable boxes with one box in cold standby
    for either one.
    
    Mike N.
    p.s. the other box would more than likely have to support a WNT
    partition on it's other drive and thus my concerns.