On 3/25/11 10:58 AM, Vieri Di Paola wrote: > > > --- On Thu, 3/24/11, Tom Eastep <[email protected]> wrote: > >>> --- On Thu, 3/24/11, Vieri Di Paola <[email protected]> >> wrote: >>> >>>> If I setup eth0 and eth1 as routed interfaces (no >> bridge) >>>> on "SW BOX 1" I need to do masquerading of the loc >> zone. >>> >>> Or maybe not... >>> >> >> Probably not -- use proxy ARP instead of a bridge. > > Could I merely specify the “proxyarp” option on both of my firewall > interfaces in /etc/shorewall/interfaces? > > LOC (10.215.0.0) <-> eth0 (10.215.144.91) "proxyARP option" - shorewall $FW - > eth1 (172.16.0.1) "proxyARP option" <-> NET eth0 (172.16.0.2) - Multi-ISP > shorewall gateway -> Internet >
Yes. On the upstream interface, your subnet mask should be 255.255.255.255 (/32) and you add a single host route to the upstream router. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Enable your software for Intel(R) Active Management Technology to meet the growing manageability and security demands of your customers. Businesses are taking advantage of Intel(R) vPro (TM) technology - will your software be a part of the solution? Download the Intel(R) Manageability Checker today! http://p.sf.net/sfu/intel-dev2devmar
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
