Configuring NetScreen Firewalls

Taking Advantage of the Full NSRP

By now we have explored most aspects of NSRP, but there are still a few important areas remaining. One of the shortcomings of NSRP-Lite is that in the case of failover, any existing session and VPN information (among other things) is lost. Juniper/NetScreen has an answer to this problem as well. It is called RTO mirroring, and is only available with the full NSRP.

A second shortcoming of NSRP-Lite is that in an NSRP cluster, one firewall ends up sitting unutilized for most of the time. It can be hard to justify the purchase of an additional firewall when management counters with the argument, "It says here that it will not actually be used. Why do you expect me to spend $$$ on something that will not be used?" The setups we have looked at so far are what are referred to as Active/Passive setups one firewall is active and the other is passive. NSRP provides the ability to create Active/Active configurations, in which both firewalls actively handle traffic. Designing the network for Active/Active setups requires careful consideration, but once you have it set up and working, your network will run very nicely.

In this section, we also examine a full-mesh setup, where we combine just about everything that has been discussed in this chapter into one concrete example. Let's start by looking at RTO mirroring.

Synchronizing State Using RTO Mirroring

As mentioned throughout this chapter, a failover between two firewalls can be very disruptive;

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Storage Resource and Replication Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.