top | item 36615504

(no title)

vgivanovic | 2 years ago

What is pfsync and why do I care?

discuss

order

generalizations|2 years ago

> pfsync is a computer protocol used to synchronise firewall states between machines running Packet Filter (PF) for high availability. It is used along with CARP to make sure a backup firewall has the same information as the main firewall. When the main machine in the firewall cluster dies, the backup machine is able to accept current connections without loss.

https://en.wikipedia.org/wiki/Pfsync

Looks pretty cool. Had no idea this existed, but glad to hear about it.

woleium|2 years ago

not just die, it allows you to run scheduled updates without interrupting service. I can update our gateways during the day without folks complaining.

It's been a feature of pfsense for many years (the smart kids have moved onto opensense now though)

tremon|2 years ago

http://man.openbsd.org/pfsync has more details. This is interesting, I also didn't know of its existence. That said, I've never had to administer multiple failover firewalls so my interest is purely out of curiosity.

vgivanovic|2 years ago

Thank you.