replying to myself..

On 4/28/14, 6:11 PM, Julian Elischer wrote:
On 4/28/14, 5:44 PM, Andrea Venturoli wrote:
On 04/28/14 11:18, Andreas Nilsson wrote:

You could put all the services which are on 2.0.0.2 in a separate fib and
there have another default-route.

Thanks, but unfortunately I can't, since some services must be able to answer on both addresses.

the answer is to use the ipfw setfib rule for incoming packets on the second interface.
setfib 1 ip from any to any in recv em0
In new freebsd kernels you can do this with ifconfig em0 fib 1 (I think that's the syntax) without involving ipfw.

then the session will inherit that fib. Outgoing packets from that session will use fib 1 while other outgoing packets will use fib0.
from the ifconfig man page. (FreeBSD 11 but I think it's in 10 too.)

   fib fib_number
             Specify interface FIB.  A FIB fib_number is assigned to all
frames or packets received on that interface. The FIB is not
             inherited, e.g., vlans or other sub-interfaces will use the
default FIB (0) irrespective of the parent interface's FIB. The kernel needs to be tuned to support more than the default FIB
             using the ROUTETABLES kernel configuration option, or the
             net.fibs tunable.

this can be simulated using ipfw setfib should you not have it in the release you are running.



Maybe I could use socket in one fib to proxy to the other, but that would probably make a mess in the logs when I have to identify who connects to what and from where.

 bye & Thanks
    av.
_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"


_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"



_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"

Reply via email to