load balancing firewall traffic

From: Scott Smith <scott#kontera.com>
Date: Mon, 21 Apr 2008 11:27:48 -0700


Hi, so now that we've been using haproxy very successfully for the past 4 months, it is time to see what other uses it can provide us :)

I was curious if anyone has used haproxy to load balance outbound firewall traffic?

I would like to set up a few machines running pf, and have haproxy balance outbound tcp connections through them. http traffic should be fairly simply, as I will also have squid on each pf machine. Each pf machine will have an internal and external interface, only allowing outbound traffic from the haproxy servers themselves.

Requests will be sent to an internal hostname that resolves to an IP on which haproxy is bound. It will balance the traffic to squids listening on each of the pf servers, which will then proxy the requests to the actual servers on the Internet.

Any input? What about other protocols?

-scott

--

Scott Smith, scott#kontera.com Received on 2008/04/21 20:27

This archive was generated by hypermail 2.2.0 : 2008/04/21 20:30 CEST