27 – Stateful Firewall devices and DCI challenges – Part 1
Stateful Firewall devices and DCI challenges
Having dual sites or multiple sites in Active/Active mode aims to offer elasticity of resources available everywhere in different locations, just as with a single logical data center. This solution brings as well the business continuity with disaster avoidance. This is achieved by manually or dynamically moving the applications and software framework where resources are available. When “hot”-moving virtual machines from one DC to another, there are some important requirements to take into consideration:
- Maintain the active sessions stateful without any interruption for hot live migration purposes.
- Maintain the same level of security regardless the placement of the application
- Migrate the whole application tier (not just one single VM) and enable FHRP isolation on each side to provide local default gateway (which works in conjunction with the next bullet point)
- While maintaining the live migration, it can be crucial to optimise the workflow and reduce the hair-pining effect as much as we can since it adds latency. As such, the distances between the sites as well as the network services used to optimize and secure the multi-tier application workflows amplify the impact of performances.
As with several other network and security services, the Continue reading