HA firewall with floating ip on AWS

Aus crazylinux.de
Zur Navigation springen Zur Suche springen

1 Setup

We’re going to explore high availability and load balancing using Keepalived and conntrackd.

Keepalived is a routing software designed to provide simple and robust facilities for load balancing and high-availability to Linux systems and Linux-based infrastructures.

In order to overcome the problem, we have to deploy conntrackd in FW1 and FW2. The daemon replicates the state of the connection forwarded by the active node so that the backup can takeover the connection in an appropiate way. We can dump the status of the connections forwarded by the active node:


1.1 keepalived as cluster software

https://blog.logentries.com/2014/12/keepalived-and-haproxy-in-aws-an-exploratory-guide/

1.2 floating ip on aws

map ElasticIP to cluster instances

1.3 iptables with conntrack

http://conntrack-tools.netfilter.org/testcase.html http://conntrack-tools.netfilter.org/manual.html


2 Links

2.1 Alternatives