|
From: Jim H. <jim...@gm...> - 2005-08-24 22:53:33
|
I'm posting here rather than the general list as I am interested to know what Devil developers/maintainers think with respect to the direction some patches are going. The story: Greedy souls that we are, we deployed several Devil-based firewalls in dual-interface configuration (two physical interfaces connected to same physical network, but on separate logical/IP subnets) to take maximum advantage of the ports available (two!). It delivers a privately addressed network riding on the general network. It is a hand-rolled Devil with kernel 2.4.27 and all /proc/sys/net/ipv4/conf/ethx/arp_filter =3D 1 This all worked swimmingly for 6 months. =20 We do not know what changed, but we've started to see signifcant number of cases of so-called "arp flux" related to particular workstations whose public addresses are advertised on the firewall's public interface. Flux occurs and the router serving the subnet/s will pick up the MAC of the private (wrong) interface for that PC instead of the (correct) public interface MAC. In reality, we did have a few cases of this, but it has gotten worse. We can't see what's triggering it. But that's not what I'm here to ask really. We've read what seems like the authoritative doc on this (including arp flux) here: http://linux-ip.net/html/ether-arp.html We've also looked at the "hidden" patches for 2.4 kernels (2.6, too, looks like) here: http://www.ssi.bg/~ja/#hidden I am curious to know a) if people have needed to resort to the hidden patch, and what their experience was, but also b) what do developers see as the future of these arp-related patches? If they are what is needed to make dual-homing-on-single-network work, are they going to be be integrated/merged at some point? One other option in front of us is to just abandon our config and go back to single interfaces. This would just involve work in the short term, but we'd like to keep our options open for when we can afford blazingly faster firewall boxes :) Jim=20 --=20 -*- Jim Hogan |