-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Tom Eastep contacted me and gave me the solution.
To meke this configuration work it's enough to specify the option "routeback" on the interface definition, like the following: /etc/shorewall/interfaces #ZONE INTERFACE BROADCAST OPTIONS net eth1 - blacklist lan eth0 - routeback,dhcp srv veth+ - routeback - From the definition of routeback, in the interface file, it wasn't clear to me that it worked with multiple interfaces too (although now it seems obvious also to me). Maybe we should specify this case in the option's description Anyway the bug should be closed. - -- Flavio Visentin GPG Key: http://www.zipman.it/gpgkey.asc There are only 10 types of people in this world: those who understand binary, and those who don't. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFFvcfvusUmHkh1cnoRAg4IAJ9fFhnvLrmwUZaNfUlKoR5SYSMy0QCePrOd CETsT9lLTjkS7l8orVJJpa8= =cv8N -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]