Re: [j-nsp] Better distribution of outbound packets

From: Kerry Schwab (Kerry.Schwab@wnco.com)
Date: Tue Oct 09 2001 - 14:19:47 EDT


This is certainly a good suggestion, but it won't work for those
sites like mine, where the servers are behind a single
firewall. ( the firewall is an H/A pair, but only one is active at a time).

The firewall doesn't support the idea of multiple default routes, and
for obvious security reasons, we don't want the firewall to accept
dynamic routing updates.

I have gone through several ideas, but I'm really more interested
in whether I can "globally subtract" the last hop count ( the ethernet
between the two routers) from BGP routes that are exchanged between
the two routers. I suspect I can't do this, just wanted the confirmation :)

==
Kerry Schwab
Kerry.Schwab@wnco.com

>>> Jesper Skriver <jesper@skriver.dk> 10/09/01 12:53PM >>>
The obvious solution would be to add a second VRRP address, where the
other M5 is primary, and have half your servers use that one, that is
probably the easiest solution.

/Jesper

-- 
Jesper Skriver, jesper(at)skriver(dot)dk  -  CCIE #5456
Work:    Network manager   @ AS3292 (Tele Danmark DataNetworks)
Private: FreeBSD committer @ AS2109 (A much smaller network ;-)

One Unix to rule them all, One Resolver to find them, One IP to bring them all and in the zone to bind them.



This archive was generated by hypermail 2b29 : Mon Aug 05 2002 - 10:42:37 EDT