[Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-26 Thread Red Baron
Greetings - Long time listener, first time caller. I am running a physical server with shorewalll 5.2.8, Rocky Linux 9.1, and FRR 8.5 I have 2 ISP and a Class C ASN that is peered to both ISP. I am using shorewall to provide basic firewall for the router, with minimal configuration. I have a se

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-26 Thread Justin Pryzby
On Wed, Apr 26, 2023 at 05:45:15PM -0500, Red Baron wrote: > I don't know if this is something that I should attempt to configure within > shorewall (multi-ISP setup and conntrack) or if there is a better way to > handle this via FRR. I don't know anything about FRR, but it sounds like you should

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-26 Thread Red Baron
I did attempt to install multi-isp, using mark columns & track options as such: ISP11 1 - eno1$GW1track ISP22 2 - eno2$GW2track I Also have "USE_DEFUALT_RT=Yes" this failed to work. I then replaced the m

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-27 Thread Norm & Audrey Henderson
Hi, I have been running Shorewall for years and recently added frrouting for internal-only OSPF. Getting rid of the route-rules and providers was necessary, it doesn’t work well for Shorewall and a routing engine to both try and manage routes. But I don’t have any external peering to worry about.At

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-27 Thread Tuomo Soini
On Wed, 26 Apr 2023 18:25:16 -0500 Red Baron wrote: > I did attempt to install multi-isp, using mark columns & track > options as such: > > ISP11 1 - eno1$GW1track > ISP22 2 - eno2$GW2track > > > I Also

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-27 Thread Red Baron
Perfect -- The start order seems to be important for the system. What I did to resolve this was setup each peering gateway when configuring with nmtui. I then removed all shorewall routing, including multi-isp. I am now successfully able to hit each ISP interface externally, and see the proper ro