Well, with a little more poking around I discover arp_announce and
arp_ignore, so I think I see what the direction is. So ignore me!
In the morning I think I'll set the former to "2" and the latter to
"1" and we'll just see what happens :)
Jim
On 8/24/05, Jim Hogan <jim...@gm...> wrote:
> I'm posting here rather than the general list as I am interested to
> know what Devil developers/maintainers think with respect to the
> direction some patches are going.
>=20
> The story: Greedy souls that we are, we deployed several Devil-based
> firewalls in dual-interface configuration (two physical interfaces
> connected to same physical network, but on separate logical/IP
> subnets) to take maximum advantage of the ports available (two!). It
> delivers a privately addressed network riding on the general network.
>=20
> It is a hand-rolled Devil with kernel 2.4.27 and all
> /proc/sys/net/ipv4/conf/ethx/arp_filter =3D 1
>=20
> This all worked swimmingly for 6 months.
>=20
> We do not know what changed, but we've started to see signifcant
> number of cases of so-called "arp flux" related to particular
> workstations whose public addresses are advertised on the firewall's
> public interface. Flux occurs and the router serving the subnet/s
> will pick up the MAC of the private (wrong) interface for that PC
> instead of the (correct) public interface MAC. In reality, we did have
> a few cases of this, but it has gotten worse. We can't see what's
> triggering it. But that's not what I'm here to ask really.
>=20
> We've read what seems like the authoritative doc on this (including
> arp flux) here: http://linux-ip.net/html/ether-arp.html We've also
> looked at the "hidden" patches for 2.4 kernels (2.6, too, looks like)
> here: http://www.ssi.bg/~ja/#hidden
>=20
> I am curious to know a) if people have needed to resort to the hidden
> patch, and what their experience was, but also b) what do developers
> see as the future of these arp-related patches? If they are what is
> needed to make dual-homing-on-single-network work, are they going to
> be be integrated/merged at some point?
>=20
> One other option in front of us is to just abandon our config and go
> back to single interfaces. This would just involve work in the short
> term, but we'd like to keep our options open for when we can afford
> blazingly faster firewall boxes :)
>=20
> Jim
>=20
>=20
> --
> -*- Jim Hogan
>=20
--=20
-*- Jim Hogan
Seattle, WA
www.drizzle.com/~jimhogan
|