Re: [leaf-user] Check for internet connection in a multiISP configuration: request about foolsm (moved to leaf-devel)
Erich Titl <[email protected]> Wed, 27 Sep 2017 12:59:34 +0200
| Newsgroups | gmane.linux.leaf.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Graziano Am 27.09.2017 um 08:37 schrieb Graziano Brioschi: > Hi Erich, > > > Il 22/09/2017 13:31, Erich Titl ha scritto: >> Hi Graziano >> >> Am 22.09.2017 um 12:38 schrieb Graziano Brioschi: >>> Hi Eric, >>> >>> here you can find the configuration file and two simple customized >>> script that i have used for the last 10 days on a firewall installed in >>> a production environment. >>> >>> We have an ALIX firewall installed with a LEAF 6.0.3 connected in >>> this way: >>> >>> * eth0: zone "net" connected to the first ISP (ISP1) 192.168.10.2 gw >>> 12.168.10.1 >>> * eth1: zone "loc" connected to the local LAN >>> * eth2: zone "net" connected to the second ISP (ISP2) 192.168.11.2 gw >>> 192.168.11.1 >>> >>> Shorewall is configured to balance our two ISP connections based on info >>> that you can find here (http://www.shorewall.net/MultiISP.html); here >>> you can also find an example that is used by Thomas Eastep >>> >>> In attachment you can find tree files: "foolsm.conf" (config file for >>> these two connections), "script.monitoring" (script for monitoring the >>> up/down status of these two connection) and "script.fault" (script to >>> react to the up/down status of these two connections). I make a link (ln >>> -s ..) to "script" so I can change the "eventscript" without restating >>> the foolsm daemon. >> >> I am wondering if this could not be done automatically. > I don't know: perhaps sending to to the foolsm process some kind of > signal using the "kill" command... >> >>> >>> As last configuration, i have loaded a static route through the right >>> path to the ping target so foolsm can reach it even if the corresponding >>> shorewall card is in "disable" state; in /etc/default/local.start i have >>> added there two lines: >> >> Isn't shorewall supposed to enable the test connection even if the >> backup is used? > The script that i'm using to check the connection runs "shorewall > disable <ISPn>", so foolsm cannot ping he related target using the right > path: the static route "force" foolsm to check the target using the > correct path (and finally it can discover that the path is in "enable" > state before run "shorewall enable <ISPn>" ) >> >> Can we build these routes automatically > I don't know shorewall very well: the simpler solution for me is to run > "ip add ..." at system startup. >> >>> >>> ip route add 81.31.148.244 via 192.168.11.1 dev eth2 # >>> target ping used for monitoring ISP2 >>> ip route add 8.8.4.4 via 192.168.10.1 dev eth0 >>> # target ping used for monitoring ISP1 >>> >>> I hope these informations can help us to build a foolsm package for LEAF >> >> Thank you very much for your help. Do you have any suggestions on >> where we should put these files initially? > I think that /etc/foolsm/sample is a good place >> >> Are the files I put in foolsm.lrp sufficient for an initial installation? > Yes OK, I might do some investigation into the shorewall settings, but for now I will just add the files to the sample directory. Should you have more information, please do not hesitate to inform us, so we can improve the package. Ciao ET ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ leaf-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/leaf-devel
smime.p7s
(application/pkcs7-signature, 1.9 KB) - not displayed