[Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-21 Thread m...@rk Lombaard
Hello, I have 2 ISP uplinks (zones: inet1 and inet2), each with a fixed IP on the outside and a routed subnet (/25 and /26) on the inside. So, behind the firewall i have 2 networksegments (lan1 and lan2) with public IP-addresses. The segments are completely isolated from eachother: hosts in

Re: [Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-21 Thread Robert K Coffman Jr. -Info From Data Corp.
I don't know if it has anything to do with your error but the below looks wrong. - Bob Coffman On 1/21/2010 4:28 AM, m...@rk Lombaard wrote: > params: > ETH0_IP=$(find_first_interface_address eth2) > ETH2_IP=$(find_first_interface_address eth0) --

Re: [Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-21 Thread m...@rk Lombaard
What should it be then? I can clear the 'params' file, but what should I put in 'masq' instead of the variables? _ Download gratis emoticons voor Messenger http://www.rulive.nl/aspx/e

Re: [Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-21 Thread Tom Eastep
m...@rk Lombaard wrote: > tcfilters: > #INTERFACE: SOURCE DESTPROTO DESTSOURCE > TOSLENGTH > #CLASS PORT(S) PORT(S) > 1:Peth10.0.0.0/0 all > 2:Peth30.

Re: [Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-23 Thread Tom Eastep
On Thu, 2010-01-21 at 10:40 +0100, m...@rk Lombaard wrote: > Graphical overview attached And what, pray tell, are we supposed to do with that? -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washin

Re: [Shorewall-users] Shorewall 4.4.6 and Multiple ISP with 2 routed subnets

2010-01-23 Thread Tom Eastep
On Sat, 2010-01-23 at 19:29 -0800, Tom Eastep wrote: > On Thu, 2010-01-21 at 10:40 +0100, m...@rk Lombaard wrote: > > Graphical overview attached > > And what, pray tell, are we supposed to do with that? Please disregard -- I just realized that Mark's post was sent two days ago and just arrived t