Tom,

I've had moderate success with this config.  The main problem is with
traffic coming across the T1/telco firewall and into the LAN.  There is an
IPSec endpoint within the LAN and some port-mapped rules on the telco
firewall.  Since Shorewall sits between the telco firewall and LAN, that
traffic doesn't know where to go once it reaches the Shorewall <---> Telco
FW segment.

It would seem that I'd almost have to set-up ARP proxying for every internal
IP address that the telco firewall needs to talk to.  Am I correct?  Is
there a cleaner way of doing this?  Thanks!

On Thu, Aug 11, 2011 at 1:33 PM, Tom Eastep <[email protected]> wrote:

>
> On Aug 11, 2011, at 9:45 AM, Jamie Begin wrote:
>
> Thanks for the quick suggestion, Tom.  I'll be giving it a shot this
> evening.  Would using the ARP proxy config still allow me to load-balance
> across the connections and use LSM for failover?
>
>
> Yes.
>
> -Tom
>
>    Tom Eastep        \ When I die, I want to go like my Grandfather who
> Shoreline,         \ died peacefully in his sleep. Not screaming like
> Washington, USA     \ all of the passengers in his car
> http://shorewall.net \________________________________________________
>
>
>
>
> ------------------------------------------------------------------------------
> Get a FREE DOWNLOAD! and learn more about uberSVN rich system,
> user administration capabilities and model configuration. Take
> the hassle out of deploying and managing Subversion and the
> tools developers use with it.
> http://p.sf.net/sfu/wandisco-dev2dev
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>
>
------------------------------------------------------------------------------
EMC VNX: the world's simplest storage, starting under $10K
The only unified storage solution that offers unified management 
Up to 160% more powerful than alternatives and 25% more efficient. 
Guaranteed. http://p.sf.net/sfu/emc-vnx-dev2dev
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to