On 04/13/2016 01:08 AM, [email protected] wrote: > Hello! > > Reading your explanation this makes sense to a certain degree. > However, I have no issue when modifying the conguration: > > root@pc4-svp:/etc/shorewall# cat providers > #NAME NUMBER MARK DUPLICATE INTERFACE > GATEWAY OPTIONS COPY > um_business 1 0x10000 - UMB_IF > detect track,balance > um_private 2 0x20000 - UMP_IF > 192.168.1.1 loose > > root@pc4-svp:/etc/shorewall# ip rule ls > 0: from all lookup local > 999: from all lookup main > 1000: from 217.8.50.86 lookup um_business > 1000: from 192.168.1.14 lookup um_private > 10000: from all fwmark 0x10000/0x30000 lookup um_business > 10001: from all fwmark 0x20000/0x30000 lookup um_private > 11000: from 10.1.0.1 lookup um_business > 20000: from 217.8.50.86 lookup um_business > 32765: from all lookup balance > 32767: from all lookup default > > Based on this there's a relation to the configuration of options "track" > and "loose" in /etc/shorewall/providers. >
Let's back up here and ask why you believe that you need a default route on vmbr2? If the KVM and LXC clients in 192.168.178.0/24 use 192.168.178.1 as their default gateway rather than 192.168.178.10, then there is no reason that I can see to require a default route on the bridge. Am I missing something? -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Find and fix application performance issues faster with Applications Manager Applications Manager provides deep performance insights into multiple tiers of your business applications. It resolves application problems quickly and reduces your MTTR. Get your free trial! https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
