On 03/04/2013 02:45 PM, Ruth Ivimey-Cook wrote:
> Robert
> 
> Thanks for your reply
>> Not sure what you mean by a "default server" so I'm not sure I can help
>> on that point.
> That's what it's called in the config...   There are options for sending 
> traffic for specific ports to other IPs, so e.g. you can send port 80 
> traffic to IP1, port 25 traffic to IP2... there's also a default IP (the 
> default server) to send anything for ports not otherwise listed. I guess 
> it's a kind of simplistic routing table.
> 
> I found that leaving this out of the modem's config means it doesn't 
> route properly when the internal IP is not that of the gateway.
> 
> I guess I replace this with a simple routing rule on the gateway and 
> it's not really a shorewall thing?
> 
>> On the modem - when you bridge it, usually you do lose IP access to it
>> (I've seen exceptions.)  You shouldn't need to configure it beyond the
>> bridging.  Your shorewall firewall should then be configured to do the
>> PPP auth.
> Ok.. at least I'm not misunderstanding something. It seems a strange the 
> manufacturers dont find a better solution...


It sounds to me like you pretty much want to follow the Three-interface
Shorewall Quickstart Guide. It will require three NICs in the Shorewall
box in order to retain your DMZ.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_feb
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to