Firewall Reconfiguration
We have been aware for some time that our firewall rules don't all use tagging. This is causing some issues with some webservers appearing as down in DO.
Proposed Plan
- Move mg-ub-web-004 into LB1, leaving LB2 empty
- Move mg-ub-web-002 and mg-ub-web-003 into LB2
- Tag mg-ub-web-002 and mg-ub-web-003 as 'MG Webserver'
- Review the firewall rules across all services, removing any reference to the public and private IP addresses of mg-ub-web-002 and mg-ub-web-003, as well as their host names, and replace with the tag 'MG Webserver'
- Update all configurations in: Firewall configuration
- Confirm both mg-ub-web-002 and mg-ub-web-003 are showing as 'up' in LB2
- Move mg and testmg subdomains to LB2, test for a week
- Change all subdomains to point to the public IP of LB2, effectively making LB2 our master LB
- Tag mg-ub-web-001 and mg-ub-web-004 as 'MG Webserver'
- Confirm both mg-ub-web-001 and mg-ub-web-004 are showing as 'up' in LB1
- Move mg-ub-web-002 back into LB1
- Move mg-ub-web-004 back into LB2