[Shorewall-users] Issues with default route

2021-07-24 Thread Norman and Audrey Henderson
Hi, I have been using rt_rules to force certain traffic out one or the other of my iSP's, and it has worked will for years. I seem to have done "something" that has caused the following behavior. One ISP is vlan5 and it's flaky. The other is vlan7 and it's mostly stable. The two ISP's are set up w

Re: [Shorewall-users] Issues with default route

2021-07-24 Thread Justin Pryzby
On Sat, Jul 24, 2021 at 01:38:17PM +0100, Norman and Audrey Henderson wrote: > Hi, I have been using rt_rules to force certain traffic out one or the > other of my iSP's, and it has worked will for years. I seem to have done > "something" that has caused the following behavior. It sounds like an O

Re: [Shorewall-users] Issues with default route

2021-07-24 Thread Norman and Audrey Henderson
Thanks Justin, yes it would be a good idea to manage my configs ... This is Ubuntu 20.04 with netplan. vlan5 is a dhcp interface however vlan7 is static and produces the same behavior. No it doesn't seem like shorewall is doing it. /var/log/shorewall-init.log doesn't record anything. For now I wi

Re: [Shorewall-users] Issues with default route

2021-07-24 Thread Erich Titl
Hi Norm Am 24.07.2021 um 14:38 schrieb Norman and Audrey Henderson: Hi, I have been using rt_rules to force certain traffic out one or the other of my iSP's, and it has worked will for years. I seem to have done "something" that has caused the following behavior. One ISP is vlan5 and it's flaky

Re: [Shorewall-users] Issues with default route

2021-07-25 Thread Norman and Audrey Henderson
Thank you Erich. I would have suspected DHCP, except that vlan7 has a static IP in Netplan and if I flip it down and up again, there is a static route added for its gateway to the ip route table main, just as happens with a recycle of vlan5 which is DHCP. A mystery. I have a working bypass for now

Re: [Shorewall-users] Issues with default route

2021-07-26 Thread Tuomo Soini
On Sat, 24 Jul 2021 13:38:17 +0100 Norman and Audrey Henderson wrote: > However if vlan5 goes down briefly or if I simulate that by: ifconfig > vlan5 down; sleep 2; ifconfig vlan5 up - then a default route to the > gateway of vlan5 gets added to table main. The preference for vlan7 > (being after

Re: [Shorewall-users] Issues with default route

2021-07-26 Thread Norman and Audrey Henderson
Thanks Tuomo. The interfaces of course require a gateway since they are not point-to-point. Today I disabled foolsm so I am sure those scripts are not doing anything. I cannot guess what other system component could be reacting to a change in interface status and creating a default route in table

Re: [Shorewall-users] Issues with default route

2021-07-26 Thread Tuomo Soini
On Mon, 26 Jul 2021 19:38:42 +0100 Norman and Audrey Henderson wrote: > The interfaces of course require a gateway since they are not > point-to-point. You missed the point. Interface scripts must not add gateway when you do multi-isp. If you down/up interface and scripting add gateway, then run

Re: [Shorewall-users] Issues with default route

2021-07-27 Thread Norman and Audrey Henderson
Thanks again. I discovered a source that I had not thought about before: gateways defined along with static IP's in the netplan configuration; I removed those. The other source is dhcp. I removed "routers" from the "request" list in dhclient.conf and to be sure added a script under /etc/dhcp/dhclie