|
Guys,
I setup the OpenBSD+PF+Carp+pfsync firewall cluster at ISG. I’m very happy with the results. The configuration is basic and not too exotic. We’ve got a handful of subnets behind the cluster hosting a variety of public services (dns, web, smtp, pop, imap, instant messaging, VOIP and others.)
My favorite feature of the cluster has always been the CARP automatic fail-over. We can service one node (firmware/OS upgrades) without affecting service.
The SCOSUG.org site is on our network behind this firewall.
It was simple to setup and just works.
-joe
|