|
From: Steve R. <Ste...@sa...> - 2010-04-21 14:52:52
|
Bruce, This does not help the high speed firewall swap to standby hardware. The NIC sequence as the cold-standby starts up might require manual configuration. Regards - Steve. -----Original Message----- From: Bruce Smith [mailto:bw...@re...] Sent: 21 April 2010 15:47 To: dev...@li... Subject: Re: [Devil-linux-develop] /etc/udev/rules.d/70-persistent-net.rules and /etc/mactab Another idea I just came up with is to add an option to save-config to save a new config file with a different name, omitting all hardware specific files, who's purpose is to be transferred to a different machine. And since the new saved config file has a different name, there is no chance of it being used upon boot by mistake, without manual renaming. To do this, we'd need to come up with a list of files to omit. Probably more than just the NIC related files. LVM files? Others? That might be the quickest and easiest solution. Thoughts? - BS On Wed, Apr 21, 2010 at 10:40, Steve Ralph <Ste...@sa...> wrote: > OK, thanks everyone. > > Taking on board everyone's comments to date, I'll combine my initial bug/feature requests into a new proposal. > > As the absence of "70-persistent-net.rules" may not generate the NIC assignments in the same order (which I agree could be disastrous for a firewall) then I now think that the present behaviour of save-config including "70-persistent-net.rules" should be retained. > > My test-environment on a usb-stick (used on differing hardware) is conceptually the same as Stefan's requirement to fail-over a saved config onto a cold standby box. While the impact on my usb test-build to correct persistent mac assignment is no real problem, if you are failing over a firewall you want a speedy swapover with as little messing as possible, assuming always that you have configured this upfront. > > Just patching /etc/init.d/network to call /sbin/nameif to align interfaces and mac-addresses will not, on it's own, address this scenario. > > What enabling a call to nameif and mactab does do is allow an administrator to take control of interface assignment, rather than having to work with whatever udev saves in 70-persistent-net.rules. > > My colleague Roy (the "linux-nut" of previous posts) has a proof-of-concept bash-script that reads a separate new config file /etc/mactable.conf pre-populated with multiple interface/mac-address details from *both* the current-active and the cold-standby hardware, and greps to populate /etc/mactab with only the entries relating to addresses discovered by "ifconfig -a". This would need to be called earlier in the startup sequence than network startup, which would then find a valid /etc/mactab for the booting hardware. > > Sequencing would need to be as follow (pseudo code): > > if /etc/mactable.conf exists > then create or overwrite /etc/mactab from /etc/mactable.conf > fi > if /etc/mactab exists > then call nameif to use it > else > use the current behaviour (Eg: 70-persistent-net.rules) > fi > > So, if the requirement is to assign mac addresses to specific devices on a single system edit /etc/mactab, or If the requirement is to assign differect mac addresses to specific devices on a failover systems edit /etc/mactable.conf. > > Does this sound to be a way forward? > > Regards - Steve. > ------------------------------------------------------------------------------ _______________________________________________ Devil-linux-develop mailing list Dev...@li... https://lists.sourceforge.net/lists/listinfo/devil-linux-develop |