2009-05-12 14:02:19 UTC
Another piece of info is that the router's gateway is the vuurmuur box so traffic runs from a 10.1.1 device to vuurmuur and then to the router and across to the 10.3.3 network, the opposite way for the return path ( symmetric route ); device on 10.3.3 net to vuurmuur and then to 10.1.1 device ...
I've popped in my old firewall script for the moment ( Monmotha's script ) just to get things working in the meantime. Seeing that this works, I took a look at what it was doing and found that the 10.3.3 network ( and some others that are routed as well ) were masqueraded. Could this be the problem? ie. non-directly connected networks need to be masq'd ( even though they are not NAT'd )
Regards, Robby