Active-active HA state-full firewall and DHCPv6

Here is a quick summary of this topic and topology configuration:

Two Remaining Problems:

  1. DHCPv6 Compatibility with HA on VyOS 1.4:
  • DHCPv6 is not currently supported with High Availability (HA) on VyOS 1.4. The proposed solution involves replacing ISC DHCP with Kia. Using 1.4 as-is introduces potential complications when one router is down, especially if a lease expires during that period. The inclusion of this fix in VyOS 1.4 remains uncertain. We highly anticipate implementing this feature; it looks like it is planned only in 1.5.
  1. Conntrack-Sync Limitations with VRRP in VyOS:

Additional Feature Request:

  1. Dynamic IP Network List Download for Firewall Configuration:
  • Dynamically download a list of IP networks from an online file to add to the firewall. For us, this feature, categorized as a “nice-to-have,” is uncertain for inclusion even in VyOS 1.5. Meanwhile, we accept Python script workaround that can be periodically executed on VyOS. Hence, there is a workaround in place, and we can wait for a potential future implementation.
1 Like