[Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jan Mulders
Hello all. Having a few troubles with ProxyARP - Despite being configured in what looks to be a correct manner, my server is not responding to incoming ARP queries. Take a look: One machine (external to this entire network) pinging 67.159.49.180, a client on my VPN interface, tun0: seeds:~# ping

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jerry Vonau
Jan Mulders wrote: > Hello all. > > Having a few troubles with ProxyARP - Despite being configured in what > looks > to be a correct manner, my server is not responding to incoming ARP > queries. > Take a look: > > One machine (external to this entire network) pinging 67.159.49.180, a > client on

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jan Mulders
I can't ping .177... Perhaps it's the broadcast address for my IP range: if another machine can't find my mac address, it sends it to the broadcast address which spams it out over my subnet? [EMAIL PROTECTED] [~]# ping 67.159.49.177 PING 67.159.49.177 (67.159.49.177) 56(84) bytes of data. --- 67

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jan Mulders
Oh, forgot a route dump: [EMAIL PROTECTED] [~]# route -n Kernel IP routing table Destination Gateway Genmask Flags Metric RefUse Iface 67.159.49.182 0.0.0.0 255.255.255.255 UH0 00 tun0 67.159.49.183 0.0.0.0 255.255.255.255 UH0 0

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Tom Eastep
Jan Mulders wrote: > Oh, forgot a route dump: I suspect that Jerry was asking for a 'shorewall dump'. I know that I won't look at this problem until I have one in hand. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington U

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jerry Vonau
Jan Mulders wrote: > I can't ping .177... Perhaps it's the broadcast address for my IP range: if > another machine can't find my mac address, it sends it to the broadcast > address which spams it out over my subnet? > If I can ping .177 and you can't, as a guess, it sounds like your missing a rou

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jan Mulders
After noting your observations regarding a lack of being able to ping .177, I have successfully diagnosed that there was a missing route to this IP address (because I was using a /24 netmask for my tun0 interface). Some further investigation to try and obtain the right method of configuring this

Re: [Shorewall-users] Troubleshooting ProxyARP

2007-06-10 Thread Jerry Vonau
Jan Mulders wrote: > After noting your observations regarding a lack of being able to ping .177, > I have successfully diagnosed that there was a missing route to this IP > address (because I was using a /24 netmask for my tun0 interface). > > Some further investigation to try and obtain the right