On 08/02/2017 06:02 AM, Vieri Di Paola via Shorewall-users wrote: > > ________________________________ > From: Vieri Di Paola via Shorewall-users > <[email protected]> >> >> # tcpdump -nni enp6s0 icmp > > > I think I just found a solution, but I still need to understand why. > > I had to add proxyarp=1 to the wan interface in "interfaces". Pings to wan > hosts started working. > > Funny thing is that if I set proxyarp=0 and restart shorewall the pings still > work. They stop working only if I reboot the kernel (waiting doesn't seem to > make the pings fail either - there doesn't seem to be a timeout or similar). > Resetting proxyarp=1 and restarting shorewall works as expected. > > I still have to understand why this interface requires proxyarp, and the > other interfaces don't. >
A current dump of fw1 might shed some light on that... -Tom -- Tom Eastep \ Q: What do you get when you cross a mobster with Shoreline, \ an international standard? Washington, USA \ A: Someone who makes you an offer you can't http://shorewall.org \ understand \_______________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
