--- On Fri, 3/25/11, Tom Eastep <[email protected]> wrote:

> > --- On Thu, 3/24/11, Tom Eastep <[email protected]>
> wrote:
> > 
> >>> --- On Thu, 3/24/11, Vieri Di Paola <[email protected]>
> >> wrote:
> >>>
> >>>> If I setup eth0 and eth1 as routed
> interfaces (no
> >> bridge)
> >>>> on "SW BOX 1" I need to do masquerading of
> the loc
> >> zone.
> >>>
> >>> Or maybe not...
> >>>
> >>
> >> Probably not -- use proxy ARP instead of a
> bridge.
> > 
> > Could I merely specify the “proxyarp” option on
> both of my firewall interfaces in
> /etc/shorewall/interfaces?
> > 
> > LOC (10.215.0.0) <-> eth0 (10.215.144.91)
> "proxyARP option" - shorewall $FW - eth1 (172.16.0.1)
> "proxyARP option" <-> NET eth0 (172.16.0.2) -
> Multi-ISP shorewall gateway -> Internet
> > 
> 
> Yes. On the upstream interface, your subnet mask should be
> 255.255.255.255 (/32) and you add a single host route to
> the upstream
> router.

Sorry I'm off-track (first time trying out proxy ARP) but What is exactly the 
"upstream interface"? Is it $FW's eth0 in my example?

Do you mean the following?

LOC (10.215.0.0/255.255.0.0) <-> eth0 (10.215.144.91/255.255.255.255) "proxyARP 
option" - shorewall $FW - eth1 (172.16.0.1/255.255.255.240) "proxyARP option" 
<-> NET eth0 (172.16.0.2/255.255.255.240) - Multi-ISP shorewall gateway -> 
Internet



------------------------------------------------------------------------------
Enable your software for Intel(R) Active Management Technology to meet the
growing manageability and security demands of your customers. Businesses
are taking advantage of Intel(R) vPro (TM) technology - will your software 
be a part of the solution? Download the Intel(R) Manageability Checker 
today! http://p.sf.net/sfu/intel-dev2devmar
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to