I'm currently using a linux box to handle my firewall/NAT using iptables. It has two NICs, one link to a LAN switch, one to our egress Internet provider. I'm looking at upgrade this box to two boxes for purposes of redundancy and adding a second Internet provider to the solution. This means I need four ports I believe (correct me if I'm wrong)
- Egress internet link #1
- Egress internet link #2
- LAN port
- Cross-over between the two boxes for failover purposes
I've read carp+pfsync is a good solution. Is that currently what most of you are using? Is there an equivalent solution in linux?
What are some suggestions for hot failover with ease of configuration as of today for a similar setup as above?