[Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Mike Lander
I have a two Isp's setup that send mail to another two Isp firewall. For Ilustration I will call the firewall with the mail server in its dmz using proxy arp, (Firewall A). I will call the dependant firewall which sends mail to Firewall A, (Firewall B.) These two Firewall's have a openvpn tunnel

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Mike Lander
> > I have a two Isp's setup that send mail to another two Isp firewall. > For Ilustration I will call the firewall with the mail server in its dmz > using proxy arp, > (Firewall A). I will call the dependant firewall which sends mail to Firewall > A, (Firewall B.) > These two Firewall's have

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Tom Eastep
Mike Lander wrote: > >> I have a two Isp's setup that send mail to another two Isp firewall. >> For Ilustration I will call the firewall with the mail server in its dmz >> using proxy arp, >> (Firewall A). I will call the dependant firewall which sends mail to >> Firewall A, (Firewall B.) >> The

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Tom Eastep
Mike Lander wrote: > >> I have a two Isp's setup that send mail to another two Isp firewall. >> For Ilustration I will call the firewall with the mail server in its dmz >> using proxy arp, >> (Firewall A). I will call the dependant firewall which sends mail to >> Firewall A, (Firewall B.) >> The

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Mike Lander
> Mike Lander wrote: > > > >> I have a two Isp's setup that send mail to another two Isp firewall. > >> For Ilustration I will call the firewall with the mail server in its dmz > >> using proxy arp, > >> (Firewall A). I will call the dependant firewall which sends mail to > >> Firewall A, (Fire

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Tom Eastep
Mike Lander wrote: >> Mike Lander wrote: I have a two Isp's setup that send mail to another two Isp firewall. For Ilustration I will call the firewall with the mail server in its dmz using proxy arp, (Firewall A). I will call the dependant firewall which sends mail to Fir

[Shorewall-users] Shorewall is amazing! (New Multi-ISP and USE_DEFAULT_RT=Yes)

2009-10-16 Thread Keith Mitchell
Wow. Just wow. Started using the new Shorewall Multi-ISP features and USE_DEFAULT_RT=Yes. Was totally confused when running "ip route" and seeing there was no default route any more! Reading the instructions though, "ip rule ls" and "shorewall show routing" both were clear that my routes were s

Re: [Shorewall-users] Shorewall is amazing! (New Multi-ISP and USE_DEFAULT_RT=Yes)

2009-10-16 Thread Tom Eastep
Keith Mitchell wrote: > Wow. Just wow. Started using the new Shorewall Multi-ISP features and > USE_DEFAULT_RT=Yes. Was totally confused when running "ip route" and seeing > there was no default route any more! > > Reading the instructions though, "ip rule ls" and "shorewall show routing" > bot

Re: [Shorewall-users] Multi-Isp Route port 25

2009-10-16 Thread Mike Lander
> > Mike Lander wrote: > > > > > >> I have a two Isp's setup that send mail to another two Isp firewall. > > >> For Ilustration I will call the firewall with the mail server in its dmz > > >> using proxy arp, > > >> (Firewall A). I will call the dependant firewall which sends mail to > > >> Fi

Re: [Shorewall-users] Multi-ISP, USE_DEFAULT_RT=Yes, and I am an idiot - Part A

2009-10-16 Thread Keith Mitchell
I'm trying to connect a branch office to my main office. I have data and voice that need to flow between the branch office and the main one. I have a VPN setup for the data, and a dedicated fiber trunk between the two offices. I thought I'd try to use the Multi-ISP setup to help segment the

Re: [Shorewall-users] Multi-ISP, USE_DEFAULT_RT=Yes, and I am an idiot - Part B

2009-10-16 Thread Keith Mitchell
Part B as attachments were too big. Keith Mitchell CTO Productivity Associates, Inc. 5625 Ruffin Rd STE 220 San Diego, CA 92123 858-495-3528 (Direct) 858-495-3540 (Fax) networkb.bz2 Description: Binary data -- Come bui

Re: [Shorewall-users] Multi-ISP, USE_DEFAULT_RT=Yes, and I am an idiot - Part C

2009-10-16 Thread Keith Mitchell
Sigh. Fixed my pretty little ascii art. eth1 - 10.253.0.1 eth3 - 10.253.0.254 eth0 /---\ eth0 192.168.1.1/24 --- Office A - - Office B --- 10.254.0.1/24

Re: [Shorewall-users] Multi-ISP, USE_DEFAULT_RT=Yes, and I am an idiot - Part A

2009-10-16 Thread Christ Schlacta
if you have dedicated fiber, why are you bothering with the overhead of vpn as well? Keith Mitchell wrote: > I'm trying to connect a branch office to my main office. > > I have data and voice that need to flow between the branch office and > the main one. > > I have a VPN setup for the data, a

Re: [Shorewall-users] Multi-ISP, USE_DEFAULT_RT=Yes, and I am an idiot - Part A

2009-10-16 Thread Larry
Christ Schlacta wrote: if you have dedicated fiber, why are you bothering with the overhead of vpn as well? Probably an IPSec tunnel to encrypt the data? Just a guess smime.p7s Description: S/MIME Cryptographic Signature -