Firewalls: Difference between revisions

From JCWiki
Jump to navigation Jump to search
No edit summary
No edit summary
 
Line 1: Line 1:
= Overview =
= Overview =


We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on.
We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on and running no ipfw rules, so when it's plugged in traffic will flow quickly through it.


At i2b we have "firewall2" in cab 6. There is no backup firewall there.
At i2b we have "firewall2" in cab 6. There is no backup firewall there.

Latest revision as of 16:20, 11 October 2012

Overview[edit]

We have 3 firewall servers. At castle, in cabinet 3-8 we have "firewall" (hostname shows up as "newgateway" on shell) and a few U's below it we have "gate" which is a backup firewall. "gate" is always on and running no ipfw rules, so when it's plugged in traffic will flow quickly through it.

At i2b we have "firewall2" in cab 6. There is no backup firewall there.

switching to backup firewall ("gate") @ castle[edit]

To switch to "gate" (in case "firewall" goes down) simply move down the 2 yellow ethernet cables maintaining orientation, to gate (right cable goes to "fxp1" and left cable goes to onboard nic on "gate"):

"em1" (on "firewall") moves to "fxp1" (on "gate") - both ports are on the right
left cable ("firewall") moves to onboard nic ("gate") - both ports are on the left