[EMAIL PROTECTED] wrote:

> 1. What is the best and quickest way to make one or two changes and
> restart the shorewall so that a down ISP is removed from load
> balancing and the live isp gets all the load?
> 

Simply set the 'optional' option on both interfaces in
/etc/shorewall/providers. Then you just hae to restart Shorewall.

> 2. We have a split dns and serve all outside requests for name resolution.
> We have opened up the DNS port (53), but there are drops in the
> shorewall log file.

Insufficient data to analyze the problem. We would need a Shorewall dump
that included these log entries (generated since the last time that the
Shorewall counters were reset).

Or you could spend some time with Shorewall FAQ 17 and try to determine
why you are seeing those messages.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

Attachment: signature.asc
Description: OpenPGP digital signature

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to