On 3/25/11 10:58 AM, Vieri Di Paola wrote:
> 
> 
> --- On Thu, 3/24/11, Tom Eastep <[email protected]> wrote:
> 
>>> --- On Thu, 3/24/11, Vieri Di Paola <[email protected]>
>> wrote:
>>>
>>>> If I setup eth0 and eth1 as routed interfaces (no
>> bridge)
>>>> on "SW BOX 1" I need to do masquerading of the loc
>> zone.
>>>
>>> Or maybe not...
>>>
>>
>> Probably not -- use proxy ARP instead of a bridge.
> 
> Could I merely specify the “proxyarp” option on both of my firewall 
> interfaces in /etc/shorewall/interfaces?
> 
> LOC (10.215.0.0) <-> eth0 (10.215.144.91) "proxyARP option" - shorewall $FW - 
> eth1 (172.16.0.1) "proxyARP option" <-> NET eth0 (172.16.0.2) - Multi-ISP 
> shorewall gateway -> Internet
> 

Yes. On the upstream interface, your subnet mask should be
255.255.255.255 (/32) and you add a single host route to the upstream
router.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Enable your software for Intel(R) Active Management Technology to meet the
growing manageability and security demands of your customers. Businesses
are taking advantage of Intel(R) vPro (TM) technology - will your software 
be a part of the solution? Download the Intel(R) Manageability Checker 
today! http://p.sf.net/sfu/intel-dev2devmar
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to