pf table synchronization between redundant routers (pfsync?)

Nikolay Denev niki at totalterror.net
Sat Nov 11 11:47:18 UTC 2006


Hi all,

I'm thinking about adding support for pfsync to synchronize
pf tables, so it can be used on redundant firewalls/routers setup.

At first glance it looks fairly simple, just send/receive
a message containing the table name, the prefix, and the action "add" or 
  "remove".

Has anyone tried something like this?
The other thing that comes to my mind is for example a patched routed, 
that will work on pftables, instead of the kernel routing table?

P.S: I know about pftabled, but i'm searching about different solution.

--
Niki


More information about the freebsd-net mailing list