Roll your own. Firewalls are going to be crushed in the next couple of years by robust opensource competition. [Hijexx: Excellent work, wow... BSD licensed active/active with the IPSEC flexibility of a NetScreen or a PIX would *KILL* Check Point dead. Oh yeah, and we'd finally get CHAINS!!! :) ] [Rek: Actually, it seems like dropped connections aren't a big connection. Most people will live with this as long as they can reconnect and everything is running. It only seems like certain kinds of usage (e.g. financial transactions) require full state failover. ] High Availability OpenBSD pf Firewalls! |