Displaying 20 results from an estimated 3000 matches similar to: "nat ,dnat or proxyarp with heartbeat"
2017 Nov 01
2
Centos and xen network bridge issue
Hi All,
We have a single Centos 5.11 server running a xen hypervisor that went
down hard after an extended power outage this weekend. I'm mostly
familiar for KVM as that is the majority of what our guests run under
and have tried getting up to speed on xen bridging to no avail.
The problem is that after the xen server spun back up, the previously
defined xen bridges were lost. I've
2004 Oct 28
8
2 external IPs on one nic in addition to the regular DMZ and loc nics
I did some looking on the mailing list archives and can''t seem to find
exactly what I need, I''m also having troubles figuring this out on my
own, so if anyone has any advice, tips, whatever, that would be great.
I''ve got a machine with 3 network cards in it, one for a DMZ (with 3
machines on a switch each with a real IP address), one for the local
network on a
2002 Nov 20
8
Proxy ARP
Hi all!
I posted earlier about the proxy arp configuration =
http://shorewall.sourceforge.net/shorewall_setup_guide.htm#NonRouted, =
and was probably not sufficiently knowledgeable on the subject. I''ve =
gone through a bunch of documents on proxy arp, subnetting with proxy =
arp and the documentation at shorewall, and have come up with a setup =
that would be perfect for the job at hand
2017 Nov 01
0
Centos and xen network bridge issue
On 11/01/2017 07:55 AM, Scott Gennari wrote:
> /etc/xen/scripts/network-bridge-pcl
>
> #/bin/sh
>
> dir=$(dirname "$0")
> "$dir/network-bridge" "$@" vifnum=1 netdev=eth2 bridge=xen-dmz2
> "$dir/network-bridge" "$@" vifnum=3 netdev=eth0 bridge=xen-dmz1
Do you get any error output when you run:
/etc/xen/scripts/network-bridge
2005 May 05
1
Ping Requests issue
Tom,
I use shorewall 2.2.3 with four network interfaces comprising of three zones.
I am able to ping some servers from the internet(net-zone) and not others.
I do not want to allow ping by default from internet. I have not copied the files action.drop
and action.reject into /etc/shorewall. Nor I have a AllowPing rule in rules file.
The policy file is pasted below.
#SOURCE DEST POLICY
2004 Nov 11
12
Performance degrade going through firewall
Hi
I am using verion 2.0.10 of Shorewall.
My configuration is as follows:
Eth1 dmz1
------------| __________
| |
|
Eth2 dmz2 | FIREWALL |------| INTERNET |
----------| | _______ | |__________|
| |---------| |
2004 Dec 06
5
two firewall and shorewall
Hi,
in my lan I have two firewall, fw1 is the first and manage inte-vlan routing.
Fw2 manage internet and dmz.
fw1 and fw2 have an interface (eth4 for both fw2 and fw1) on the same
subnet that permit to the host behind fw1 to reach internet,
my problem is on fw2:
eth4 is the NIC that connect fw2 and fw1, I would''t like masquerading
hosts behind fw1, so to eth4 of fw2 arrive all
2004 Oct 09
2
odd problem with proxyarp and DNAT
I have some hosts in a DMZ zone with proxyarp. In my local zone I have a host to which I DNAT.
I have discovered that I can reach the host in the local zone by attempting to connect to the fw (As expected) or ANY proxyarped host in my dmz zone (as not expected). Is this normal ?
(I''ve just discovered that actually the dnated host answers to requests sent to any IP routed to my host!)
2004 Sep 10
1
Is ProxyARP or NAT entries really neccesary for DNAT to work?
I have been trying to get DNAT to work and I actually have succeeded
too, however, not how I thought it would work when reading through the
documentation.
1. No matter what I do I cannot get DNAT to work unless I have an entry
in eiter the nat or the proxyarp file. Is that really how it''s supposed
to be? I can''t find anything about it in the documentation.
2. Also, in the
2011 Apr 15
1
Proxyarp vs DNAT
Hello list,
I am in the process of switching from IPCOP to Shorewall s the firewall
for our small office. I very much like the fact that Shorewall runs on
top of the same OS (openSuSE 11.4) that I run on the server and my desktop.
Our setup is fairly straightforward. We have 8 static ip addresses from
our ISP, which provides a cable modem and a Cisco 800 series router.
The ip addresses are
2005 Jan 22
3
DNAT, NAT or ProxyARP?
Hello Shorewall gurus, I have a dilemma with a public server. I want to migrate the current public server over to a new machine behind the current server''s firewall (shorewall 1.4). I have included a diagram below to help explain the target network I am working toward. I have read the shorewall online documentation and though I have used Shorewall the past 4 years in the current
2004 Sep 03
7
Shorewall as a "commercial" firewall
I am considering replacing my old checkpoint and watchguard firewalls witha
single Linux box using iptables and shorewall. I have two ISP''s (with
separate routing tables), two DMZ''s, at least one VPN to a remote office, and
a local trusted network. The configuration will look like:
+----------------+
| |
net0 ----------+ eth1
2015 Jun 25
1
Possible bug in kickstart
Hello All,
I seem to have run into a bug with the new --bridgeslaves=<INTERFACE> option. It would seem that if I tell the bridge device to use a virtual interface (like bond0) rather than a physical interface (em1/em2) that kickstart completely barfs on it. I have provided my network section below which works fine as long as i don't enable all the bridge content.
When the
2005 Apr 07
4
Shorewall in a Routed network
Hi,
In a routed network environment, without the router , we want to use the shorewall as the firewall/router. The ISP has assigned the following set of IP addresses.
WAN IP for subnet 1 (DATA)
220.227.202.X/30 ( to be assigned to eth0 of the shorewall)
WAN IP for subnet 2 (Voice)
220.227.202.Y/30 ( to be assigned to eth1 of the shorewall)
Addresses assigned for Subnet 1 by
2002 Nov 11
11
Shorewall Documentation in PDF format
Hey gang,
I was wondering if all that documentation could or has been put into
PDF format. I usually like to download documentation and read it while
I''m sitting comfortably at home and I don''t want to tie up the phone
line all night.
Thanks,
Nino
p.s. If so, please feel free to attach the PDF formatted document to my
e-mail ;-)
2003 Oct 19
2
Reg. Proxyarp & DHCP
My ISP has DHCP-assigned IP-addresses.
I wonder if someone has tried using proxyarp
for a DMZ with DHCP-assigned public IP?
2005 Jan 18
1
proxyarp and masq ip
Would it be considered normal that a system behind a shorewall box that
was setup for proxyarp and able to be reached from the trusted side of
the net just fine on the proxyapr ip address would if it were to talk
out to the world show as traffic not from the proxyarp address but the
firewall''s own address or the masquerading ip used by other zones? We
had not really noticed this as an
2006 Feb 07
0
proxyarp <--> OpenSwan VPN/Internet
Our VPN runs for 3 months very well with a minimum of traffic <100 kbit/s.
Only DNS Zones and nagios passive checks were transferred. Everything seems
to work.
Left side is x.x.x.14 (host 1)
Subnet 10.0.0.0/24
openswan 2.4.4
shorewall 2.4.2 & iptables 1.3.4
gentoo 2.6.12-r9 with policy match
It´s reachable through a proxyarp entry on x.x.x.11 (host 2) which is
another gentoo 2.6.12-r9
2005 Apr 10
1
FW: ProxyARP in a Routed environment
Tom,
Is not this query worth answering?
-Siva
-----Original Message-----
From: Sivamurugu K. Pillai
Sent: Friday, April 08, 2005 3:14 PM
To: ''Mailing List for Shorewall Users''
Subject: ProxyARP in a Routed environment
Hi,
In a routed network setup , is it possible to use ProxyARP given the condition that the shorewall
external interface and the DMZ interface are in a
2004 Oct 28
5
Maximum ProxyArp
Does anyone know what a good maximum number of machines I should place
in the ProxyArp list?
Thanks
Jamie