From: Whit Blauvelt <whit@transpect.com>
To: Tom Eastep <teastep@shorewall.net>
Cc: netfilter@vger.kernel.org
Subject: Re: Could Cogent be doing packet mangling that would confuse Netfilter about interfaces?
Date: Mon, 15 Aug 2011 17:25:54 -0400 [thread overview]
Message-ID: <20110815212553.GA32552@black.transpect.com> (raw)
In-Reply-To: <1313442633.20254.7.camel@sami.shorewall.net>
On Mon, Aug 15, 2011 at 02:10:33PM -0700, Tom Eastep wrote:
> I don't have time ATM to give you detailed help, but
> http://www.shorewall.net/FoolsFirewall.html#id36131257 explains what
> happens when two firewall interfaces are effectively connected to the
> same ethernet network. That may help you figure out where the problem
> is.
Tom,
I appreciate all suggestions. I'm pretty sure the guy in charge of our
switch-and-cable infrastructure hasn't connected any switch to more than one
zone - because I've specifically asked him before, he gave me that
assurance, and he's a smart guy. But I'll ask again.
Meanwhile, if anyone else here has a suggestion, the working assumption is
that we don't have an example of the "Fool's Firewall" (as it is very
clearly explained on Tom's page) so other suggestions will also be
appreciated.
Thanks,
Whit
next prev parent reply other threads:[~2011-08-15 21:25 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-07-23 0:36 How might incoming SMB probes from public IPs be ariving on the internal interfaces? Whit Blauvelt
2011-07-25 0:01 ` Whit Blauvelt
2011-08-15 17:13 ` Could Cogent be doing packet mangling that would confuse Netfilter about interfaces? Whit Blauvelt
2011-08-15 17:52 ` Tom Eastep
2011-08-15 20:33 ` Whit Blauvelt
2011-08-15 20:47 ` Whit Blauvelt
2011-08-15 21:10 ` Tom Eastep
2011-08-15 21:25 ` Whit Blauvelt [this message]
2011-08-15 21:54 ` Grant Taylor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110815212553.GA32552@black.transpect.com \
--to=whit@transpect.com \
--cc=netfilter@vger.kernel.org \
--cc=teastep@shorewall.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.