High Availability Design
-
Hello experts!
I'm new in pfsense and I'm trying to evaluate if it's an adequate solution for our scenario. Can anybody helps me to answer some questions?
We have a high availability scenario (I'm attaching an image) in wich we need to communicate with the firewall solution using OSPF coming from different LANs and going out to the WAN at a L2 scenario where we can use the virtual shared IP address(just like VRRP) to have redundancy.
My questions are:
Can I make make this topology with pfsense?
Can I make in a way that we can still have redundancy?
Is it possible to have active/active distribution (i think we can't after reading some docs)?
Can I have LAN-to-LAN connections?
Do you recommend any change to the design to achieve this?It'll be really appreciated if anyone can answer this questions. I haven't found too much information about this kind of design.
-
Go virtual and set the scenario in ESXi….
Then use fault tolerance to enable heartbeat between the PFSense box'es. Thereby you wont need 3 external IP's provided by your ISP.
CARP on the PFSense needs 3 external IP's to start with. By std. it cannot operate with only one external IP address.