Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Firewall Distance for Storage #65

Open
majst01 opened this issue Dec 18, 2024 · 0 comments
Open

Firewall Distance for Storage #65

majst01 opened this issue Dec 18, 2024 · 0 comments

Comments

@majst01
Copy link
Contributor

majst01 commented Dec 18, 2024

In case a cluster does use storage there might be situations where the storage is located in one zone/datacenter and the firewall is located in another.
Then the storage traffic needs to cross datacenter boundaries to reach the storage VRF done by the route leak on the firewall and from there the datacenter boundary needs to be crossed again to reach the storage.
This is bad for storage latency.

To avoid this, we could spin up multiple firewalls, one for each zone/datacenter and prolong the path other destinations than storage in the storage VRF as we already do for the default routes in the internet VRF.

We can either define one firewall as "master" for the default routes and one firewall as "master" for the storage, or set the firewall which is nearest to the storage as "master" for both destinations.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant