hello.

i am trying to set up a router and a transparent tunnel point in the
same box, on the same local network. the box is a bering 1.2 with
shorewall and vtund 

the box has these interfaes
zone  if    comment
net   eth0 connected to the internet with real ip
loc   eth1 connected to local net with ip (gw for the net)
bru   eth2 connected to local net without ip, but bridged to tap0
bru   tap0 vtund ethernet tunnel tru internet to another box2
bru   br0 bridge interface bridges together eth2 and tap0


now, the box function as a masqerading router for localnetwork normaly.
the tunnel works as a bridge to another network, normaly. Remote
computers get dhcp leases from server in localnetwork and have
connectivity to localnetwork and server as expected.

but the remote computers on local network can not connect to internet,
with this box as the gateway

if i split the functions into 1 tunnel/bridge and 1 router it works as
expected. but with the increased cost of 1 box, and an additional real
ip address.

with tcpdump i can see packages going out the internet connected
interfaces (eth0) but they do not become masqueraded. packages
originating from the local side of the local net is masqueraded normaly
i have tried most available options in the masqerading file to no use.

if this is even possible, i guess there is some finer points in
shorewall that keep eluding me

thanks for your attention    

-- 
Ronny Aasen <[EMAIL PROTECTED]>
datapart AS
-- 
Ronny Aasen <[EMAIL PROTECTED]>



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to