This was apparently the heart of the problems I was having. I originally connected two separate NICs to the same switch because I had a need for two zones (loc and dmz) and only one switch. The documentation for /etc/shorewall/hosts made it sound like something I shouldn't try, and NICs are cheap, so I put another in the router box and figured it would make my life easier.

I have used multiple NICs on the same switch in the past to no ill effect, but apparently iptables doesn't play well in this environment. When I pulled one of the NICs, put an alias on eth1 for the dmz and appropriately configured hosts, all was well.

Thanks to those who offered suggestions, they provided valuable insight for understanding LEAF/Shorewall configuration.

Cheers
Chris

Ray Olszewski wrote:

Finally, could you explain a bit more about your configuration? Why does this router have 2 NICs connected to the same switch? Does this introduce any ambiguities in its routing table, or even its arp resolution?




-------------------------------------------------------
This sf.net email is sponsored by: Influence the future of Java(TM) technology. Join the Java Community Process(SM) (JCP(SM)) program now. http://ads.sourceforge.net/cgi-bin/redirect.pl?sunm0004en
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to