Re: Firewall/DMZ routing

2003-06-06 Thread Olivier Nicole
> 08:33:08.160246 arp who-has A.B.C.154 tell A.B.C.145 It looks to me as if your ISP does not know you've subnetd your subnet. If it knew, it should never try to do an arp for the subnet A.B.C.152/29 but route the ICMP to A.B.C.146 and that's it. So the router of your ISP genuinely beleive that

RE: Firewall/DMZ routing

2003-06-05 Thread Mark Thomas
> -Original Message- > From: Volker Kindermann [mailto:[EMAIL PROTECTED] > > I'm setting up a multihomed firewall box. I have all interfaces up and > > running but have something going wrong with routing. > > do you have forwarding enabled on the firewall? > > Check if: > > sysctl net.

Re: Firewall/DMZ routing

2003-06-05 Thread Volker Kindermann
Hi Mark, > I'm setting up a multihomed firewall box. I have all interfaces up and > running but have something going wrong with routing. do you have forwarding enabled on the firewall? Check if: sysctl net.inet.ip.forwarding shows: net.inet.ip.forwarding: 1 -volker __