Re: Success Stories of OSPF with a Cluster I too am of the opinion that you let routers route and firewalls firewall (I disagree on VPNs though, but that's another topic). That said, the real-world often doesn't let you put a router next to each interface on your firewall, so yo are stuck with running dynamic routing protocols on your firewalls. My personal experience with OSPF/GateD and SPLAT pro has been fine, but limited. I have heard of folks that have had problems with it. Although it seems to be a small pool of folks with problems, those problems are serious and often very similar to what melipla reports. Now back to what you want to do. By its nature OSPF is not as fast as a cluster failover but it is in general faster than replacing the router that just let out the magic blue smoke, or finding the server guy who is sure he just unpluged only the server. Think about why you want to use OSPF, and is there a better way of doing it? If not, try and keep the routing table being propagated to a minimum. |