Results 1 to 10 of 10
  1. #1
    Join Date
    Mar 2003
    Location
    Chicago
    Posts
    285

    cheapest way to do hsrp?

    We currently have zero redundancy network wise and I would like to start adding some by adding a switch or router that does hsrp since Internap is going to give us two handoffs. We currently use spanning tree but that really is not redundancy if someone hoses a router/switch config or the uplink to that switch/router goes out.

    What are some cheap (relatively speaking) ways to do hsrp? Our current "master" switch is a Dell 5324.

    Thanks,
    Scooby2

  2. #2
    HSRP is a feature that is configured on two routers that are your Default Gateay. If your servers are using Internap's router IP as default gateway, then you may not need to do HSRP at all; just a pair of switches (like your 5324).

    If you have a router or firewall in routed mode, which sits between your servers and Internap's router, then you'd need to upgrade from one router/firewall to two, and configure HSRP/VRRP between them.

  3. #3
    Join Date
    Mar 2003
    Location
    Chicago
    Posts
    285
    I have firewalls in between the servers and Internap. Everything is nat'd.

  4. #4
    Join Date
    Oct 2002
    Location
    Vancouver, B.C.
    Posts
    2,656
    HSRP is just Cisco's implementation of VRRP.

    For VRRP on the cheap, CARP on *BSD is definitely the way to go, and has even higher availability than HSRP. You can do graceful failovers with 0 packet loss using carpdemote.

    You can use VRRP on Linux as well, but I haven't used it myself so I can't comment on how well it works.
    ASTUTE HOSTING: Advanced, customized, and scalable solutions with AS54527 Premium Canadian Optimized Network (Level3, PEER1, Shaw, Tinet)
    MicroServers.io: Enterprise Dedicated Hardware with IPMI at VPS-like Prices using AS63213 Affordable Bandwidth (Cogent, HE, Tinet)
    Dedicated Hosting, Colo, Bandwidth, and Fiber out of Vancouver, Seattle, LA, Toronto, NYC, and Miami

  5. #5
    If you have firewalls, then the approach I see the most is:
    -connect each of your Internet feed cables to a separate firewall
    -configure the two firewalls into a high-availability pair
    -connect each firewall's Trust/LAN port to a different switch
    -connect the two switches together (either stacked, or with a pair of ethernet cables)
    -connect each server to both switches (failover method depends on your server OS)

    The pair of high-availability firewalls will do HSRP/VRRP/CARP or some equivalent mechanism to provide a redundant default gateway for your servers.

  6. #6
    If you don't have high-availability-capable firewalls already, the cheapest method is to use OpenBSD with pfsync. For a commercial solution, a high-availability pair of Juniper SSG-5 firewalls with extended license and rack-mount tray is a bit over $2k + $100/year.
    Last edited by Zitibake; 01-26-2008 at 09:38 PM.

  7. #7
    Join Date
    Jan 2001
    Location
    Miami, FL
    Posts
    1,072
    Can the firewalls be set into transparent mode ?
    Biznesshosting, Inc. DBA VOLICO - Intelligent Hosting Solutions
    East Coast Enterprise Dedicated Servers and Miami Colocation.
    managed and unmanaged dedicated servers. High bandwidth colocation. Managed clusters.

  8. #8
    Join Date
    Mar 2003
    Location
    Chicago
    Posts
    285
    Quote Originally Posted by bizness View Post
    Can the firewalls be set into transparent mode ?
    I was just about to ask that. Transparent or Bridging would be perfect.

    What about a Cisco router? Any way to stick a Cisco in front with 3 fast ethernet interfaces? Two from Internap and the other going to the firewalls?

  9. #9
    Join Date
    Jan 2001
    Location
    Miami, FL
    Posts
    1,072
    Quote Originally Posted by scooby2 View Post
    I was just about to ask that. Transparent or Bridging would be perfect.

    What about a Cisco router? Any way to stick a Cisco in front with 3 fast ethernet interfaces? Two from Internap and the other going to the firewalls?
    i think that he might have an issue with that since that cisco, probably 2600, will be the point of failure which he is trying to get away from.
    Biznesshosting, Inc. DBA VOLICO - Intelligent Hosting Solutions
    East Coast Enterprise Dedicated Servers and Miami Colocation.
    managed and unmanaged dedicated servers. High bandwidth colocation. Managed clusters.

  10. #10
    Join Date
    Jan 2001
    Location
    Miami, FL
    Posts
    1,072
    Quote Originally Posted by seemax View Post
    what is hrsp anyways?
    basically a floating gateway...

    .1 = floating gateway
    .2 = router1
    .3 = router 2

    .1 floats between router 1 and 2....

    This is something we do in our DC when we hand off clients their own vlan / subnet....
    Biznesshosting, Inc. DBA VOLICO - Intelligent Hosting Solutions
    East Coast Enterprise Dedicated Servers and Miami Colocation.
    managed and unmanaged dedicated servers. High bandwidth colocation. Managed clusters.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •