|
From: Jim H. <jim...@gm...> - 2005-08-25 00:44:42
|
Well, with a little more poking around I discover arp_announce and arp_ignore, so I think I see what the direction is. So ignore me! In the morning I think I'll set the former to "2" and the latter to "1" and we'll just see what happens :) Jim On 8/24/05, Jim Hogan <jim...@gm...> wrote: > I'm posting here rather than the general list as I am interested to > know what Devil developers/maintainers think with respect to the > direction some patches are going. >=20 > The story: Greedy souls that we are, we deployed several Devil-based > firewalls in dual-interface configuration (two physical interfaces > connected to same physical network, but on separate logical/IP > subnets) to take maximum advantage of the ports available (two!). It > delivers a privately addressed network riding on the general network. >=20 > It is a hand-rolled Devil with kernel 2.4.27 and all > /proc/sys/net/ipv4/conf/ethx/arp_filter =3D 1 >=20 > This all worked swimmingly for 6 months. >=20 > We do not know what changed, but we've started to see signifcant > number of cases of so-called "arp flux" related to particular > workstations whose public addresses are advertised on the firewall's > public interface. Flux occurs and the router serving the subnet/s > will pick up the MAC of the private (wrong) interface for that PC > instead of the (correct) public interface MAC. In reality, we did have > a few cases of this, but it has gotten worse. We can't see what's > triggering it. But that's not what I'm here to ask really. >=20 > We've read what seems like the authoritative doc on this (including > arp flux) here: http://linux-ip.net/html/ether-arp.html We've also > looked at the "hidden" patches for 2.4 kernels (2.6, too, looks like) > here: http://www.ssi.bg/~ja/#hidden >=20 > I am curious to know a) if people have needed to resort to the hidden > patch, and what their experience was, but also b) what do developers > see as the future of these arp-related patches? If they are what is > needed to make dual-homing-on-single-network work, are they going to > be be integrated/merged at some point? >=20 > One other option in front of us is to just abandon our config and go > back to single interfaces. This would just involve work in the short > term, but we'd like to keep our options open for when we can afford > blazingly faster firewall boxes :) >=20 > Jim >=20 >=20 > -- > -*- Jim Hogan >=20 --=20 -*- Jim Hogan Seattle, WA www.drizzle.com/~jimhogan |