--- On Fri, 3/25/11, Tom Eastep <[email protected]> wrote:
> > --- On Thu, 3/24/11, Tom Eastep <[email protected]> > wrote: > > > >>> --- On Thu, 3/24/11, Vieri Di Paola <[email protected]> > >> wrote: > >>> > >>>> If I setup eth0 and eth1 as routed > interfaces (no > >> bridge) > >>>> on "SW BOX 1" I need to do masquerading of > the loc > >> zone. > >>> > >>> Or maybe not... > >>> > >> > >> Probably not -- use proxy ARP instead of a > bridge. > > > > Could I merely specify the “proxyarp” option on > both of my firewall interfaces in > /etc/shorewall/interfaces? > > > > LOC (10.215.0.0) <-> eth0 (10.215.144.91) > "proxyARP option" - shorewall $FW - eth1 (172.16.0.1) > "proxyARP option" <-> NET eth0 (172.16.0.2) - > Multi-ISP shorewall gateway -> Internet > > > > Yes. On the upstream interface, your subnet mask should be > 255.255.255.255 (/32) and you add a single host route to > the upstream > router. Sorry I'm off-track (first time trying out proxy ARP) but What is exactly the "upstream interface"? Is it $FW's eth0 in my example? Do you mean the following? LOC (10.215.0.0/255.255.0.0) <-> eth0 (10.215.144.91/255.255.255.255) "proxyARP option" - shorewall $FW - eth1 (172.16.0.1/255.255.255.240) "proxyARP option" <-> NET eth0 (172.16.0.2/255.255.255.240) - Multi-ISP shorewall gateway -> Internet ------------------------------------------------------------------------------ Enable your software for Intel(R) Active Management Technology to meet the growing manageability and security demands of your customers. Businesses are taking advantage of Intel(R) vPro (TM) technology - will your software be a part of the solution? Download the Intel(R) Manageability Checker today! http://p.sf.net/sfu/intel-dev2devmar _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
