Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Firewalls are critical infra — by definition they can't be the least reliable device in the network.

This is why you have failover for firewalls. The loss of any single device isn't that important.



Sure but you still want them as stable as possible. Needing (emphasis there) to fail over should be for emergencies, not standard operating procedure.


> Needing (emphasis there) to fail over should be for emergencies, not standard operating procedure.

You should be failing testing failover regularly, just like you're testing backups and recovery, and other things that should not "need" to happen but have to actually work when they do.

A good time would be during your monthly/quarterly/(bi)annual/whatever patch cycle (and if there are no patches, then you should just test failover).


That’s why I emphasized “needing”.


Generally it would be part of SOP for updates requiring a service or system restart.

That said, I can't find fault in the filesystem, haven't personally encountered an issue with it, other than it being slow.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: