From mboxrd@z Thu Jan 1 00:00:00 1970 From: "San" Subject: gateway problem Date: Thu, 20 Mar 2003 23:58:50 -0300 Sender: linux-admin-owner@vger.kernel.org Message-ID: <004701c2ef55$cc96f8e0$50fbe818@sanjuan.cxm> References: <001d01c2ef04$b6374ba0$0500a8c0@castor> <1048187418.24414.106.camel@Zebra.vil.ite.mee.com> <000701c2ef54$48409ac0$0500a8c0@castor> Mime-Version: 1.0 Content-Transfer-Encoding: QUOTED-PRINTABLE Return-path: List-Id: Content-Type: text/plain; charset="iso-8859-1" To: linux-admin@vger.kernel.org hi! i=B4m new on the list, and i don=B4t know if you have discussed this be= fore or if this is the place to post this kind of problems (if not, please corr= ect me) , but it s driving me insane, so here it goes... i have a Red Hat 7.3 doing nat for an internal net of about 50 PCs. it is doing so using shorewall (a wrapper for iptables), squid (virtual= or transparent mode) and a few things with iproute2. I =B4ve always had two internet connections, a direct connetion via a C= isco Router(dont remember its model) and the other over ADSL. I=B4d managed to have the two gateways running, using the direct connec= tion for inbound traffic and as a backup for outbound connections. All the outbound trafic would go via ADSL, while it was connected and without problems. If for a reason, the ADSL went down, a script would place the direct connection as default gateway. A brief description of IPs ant interfaces: LAN Gateway(3 NICs) Internet 192.168.1.X 200.10.10.10 eth0 ---------------------------- Cisco uter -------------------------------------- 200.10.10.11 eth0:0 192.168.1.1 eth1 N/A (or a fake one) -----------------------------ADSL ------------------------= ----- ------------ 200.100.100.100 ppp0 ------------------| The gateway has two external IPs (besides the ppp0 one). One is for accessing the gateway itself, and the other for accessing an internal s= erver via DNAT. All was working properly, but suddenly people who were using the intern= al server from outside lost connection with it, even without the posibilit= y of ping'n it. Weird as it seemed to be working ok from inside. Here is where im confused. The ADSL is working ok, because it connects without problems, and NAT c= an do its job serving internet for all the local network. But when it is connected, PCs from outside cannot ping or access IPs binded to eth0 or eth0:0(alias) and yes, they can ping and access services on ppp0. If you disconnect the ADSL , and put back the gateway to have the direc= t connection all start working ok again (but considering that the traffic= on the Router is higher than we want). I checked a lot of things without success. The strange thing, leaving a= side the script that handles the changing default gateways (i mean, doing al= l by hand), is that if the ADSL is connected but you keep the default gatewa= y to the Router, it works. The moment you change the DG, it's lost. I'm sorry about the extension of this, but i couldn't find the way to describe this using less words. I hope you could understand my english = (i know is bad) and if you need more details i would be more than happy to= give them to you... i expect eagerly to hear from you all. Thank You in advance!!! Santiago Vazquez Open Computacion S.A. Buenos Aires Argentina - To unsubscribe from this list: send the line "unsubscribe linux-admin" = in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html