Firewalls: Difference between revisions
Jump to navigation
Jump to search
Created page with "= Overview = We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which..." |
No edit summary |
||
(One intermediate revision by the same user not shown) | |||
Line 1: | Line 1: | ||
= Overview = | = Overview = | ||
We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on. | We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on and running no ipfw rules, so when it's plugged in traffic will flow quickly through it. | ||
At i2b we have "firewall2" in cab 6. There is no backup firewall there. | At i2b we have "firewall2" in cab 6. There is no backup firewall there. | ||
Line 8: | Line 8: | ||
To switch to "gate" (in case "firewall" goes down) simply move down the 2 yellow ethernet cables maintaining orientation, to gate (right cable goes to "fxp1" and left cable goes to onboard nic on "gate"): | To switch to "gate" (in case "firewall" goes down) simply move down the 2 yellow ethernet cables maintaining orientation, to gate (right cable goes to "fxp1" and left cable goes to onboard nic on "gate"): | ||
"em1" (on "firewall") moves to "fxp1" (on "gate") - both ports are on the right | "em1" (on "firewall") moves to "fxp1" (on "gate") - both ports are on the right<br /> | ||
left cable ("firewall") moves to onboard nic ("gate") - both ports are on the left | left cable ("firewall") moves to onboard nic ("gate") - both ports are on the left |
Latest revision as of 16:20, 11 October 2012
Overview[edit]
We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on and running no ipfw rules, so when it's plugged in traffic will flow quickly through it.
At i2b we have "firewall2" in cab 6. There is no backup firewall there.
switching to backup firewall ("gate") @ castle[edit]
To switch to "gate" (in case "firewall" goes down) simply move down the 2 yellow ethernet cables maintaining orientation, to gate (right cable goes to "fxp1" and left cable goes to onboard nic on "gate"):
"em1" (on "firewall") moves to "fxp1" (on "gate") - both ports are on the right
left cable ("firewall") moves to onboard nic ("gate") - both ports are on the left