-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Keith Mitchell wrote:


> I think I get it.  So for starters, I need to take the firewall rules
> out of the tcrules and route_rules files to make sure the firewall(s)
> can direct traffic appropriately.

> (remove the LO lines from the route_rules and / or the "512     $FW"
> lines from the tcrules).

> I'm assuming that should clear up the routing issue also, and then I
> just have to setup a policy or ruleset to allow the tlan (10.253.0.0) to
> ping into the private net(s) if desired, otherwise the NAT will be
> working so packets should flow correctly.

Keith,

Since the point when you hijacked Mike Lander's thread, you have not
explained exactly what you are trying to accomplish. I have explained to
you what is happening but I can't tell you how to fix it until you
explain to us what you want to have happen.

Until we know that, we can't advise you about a fix until we understand
the problem being solved.

- -Tom

PS -- I assume that the "fiber tunnel" (your term) is the 10.253.0.* net?
- --
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkraMpUACgkQO/MAbZfjDLKFjgCfSWFGrR9iAPTPYlsJevty9in1
024An1evWl5mXUw/HfQh8N6raQC4lJVt
=+Uu3
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Come build with us! The BlackBerry(R) Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9 - 12, 2009. Register now!
http://p.sf.net/sfu/devconference
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to