On Oct 29, 2009, at 6:06 AM, Tom Chadwin wrote:

> All went well on-site, so it's now in production. For others who might
> want to use the Berofix (in a net5501), here is the procedure:
>
> 1. Boot the geni586 image without the Berofix installed
>
> 2. Use the Astlinux GUI to add the following to user.conf:
>
> BRIDGE0="eth0 eth1"
>
> 3. Install the Berofix, reboot, and use the GUI to set the first
> internal interface as BR0
>
> 4. Use the bfdetect tool to change the IP address of the Berofix to
> something in the same subnet as BR0
>
> Hope this helps
>
> Tom

Ahhh, the Berofix network-interface is an INTERNAL interface, not a  
shared as an external interface as I thought for some reason.

That explains why the rc.elocal example for you didn't work. :-)   
Anyway, using BRIDGE0 in user.conf is the better way to handle this  
anyway.


In 0.7 there is a new feature to allow traffic between LAN interfaces:

Network Tab -> Firewall Tab
_x_ Allow LAN to LAN for the [1st and 2nd] LAN Interfaces

Without using a bridge, this might also work for you in the future.

The Arno firewall command in 0.7 for the above is IF_TRUSTS="eth0 eth1"


In 0.6 similarly (but slightly different command), adding  
INT_IF_TRUST="eth0 eth1" would allow traffic between the two different  
LAN interface/subnets without a bridge.


Tom, thanks for documenting your experience.

Lonnie


------------------------------------------------------------------------------
Come build with us! The BlackBerry(R) Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9 - 12, 2009. Register now!
http://p.sf.net/sfu/devconference
_______________________________________________
Astlinux-users mailing list
Astlinux-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/astlinux-users

Donations to support AstLinux are graciously accepted via PayPal to 
pay...@krisk.org.

Reply via email to