1
High availability / Re: Opinion of your HA functionality
« on: February 16, 2021, 12:37:16 pm »
Hi mimugmail,
So, from your point of view its better that I forgot to apply rules on secondary firewall and once my primary firewall fails, suddenly I have service related issue which comes as a surprise. Do you think anyone would suspect that firewall blocks that traffic and do not insists that you have issues on your servers? IT will lose time and business loses money, its that simple
If you have heard Commit Confirmation functionalities, which some firewall vendors does, that would prevent you to lock your self out.
I am not sure how your though process applies in situation if you are using dynamic routing protocols? Even you lock yourself out, most likely your master is still master
So, from your point of view its better that I forgot to apply rules on secondary firewall and once my primary firewall fails, suddenly I have service related issue which comes as a surprise. Do you think anyone would suspect that firewall blocks that traffic and do not insists that you have issues on your servers? IT will lose time and business loses money, its that simple
If you have heard Commit Confirmation functionalities, which some firewall vendors does, that would prevent you to lock your self out.
I am not sure how your though process applies in situation if you are using dynamic routing protocols? Even you lock yourself out, most likely your master is still master