Barry Murphy wrote:
> Quagga is the new fork of zebra and this is what I'd like too, right
> after atheros drivers :)
>
> But from all the times I;ve asked in the past, they won't do it, this
> is a firewall not a router.
It's perfectly reasonable for a firewall device to support dynamic
routing, modern SonicWALLs running SonicOS 2 support it as do PIXes. If
you're worried about security, that's what authenticated route
advertisements are for! RIPv2, for example, supports authentication
with MD5 digests.
If you don't want your firewall to listen for dynamic routing (and have
a big enough network to need the route advertisements), feel free
to enter all those routes manually :)
--
Phil Brutsche
phil at brutsche dot us |