Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Setting up shorewall
Date: Sun, 28 May 2017 11:58:13
Message-Id: 3299631.iUrvL0pUxA@peak
In Reply to: [gentoo-user] Setting up shorewall by Peter Humphrey
1 On Wednesday 29 Mar 2017 16:59:01 I wrote:
2
3 > [I have a] new web-server box [with] two Ethernet ports, which I want to
4 > connect as follows:
5 >
6 > Port 1 (enp1s0) will be connected to [its own] port on my vDSL modem/
7 > router and be accessible from outside.
8 >
9 > Port 2 (enp2s0) is connected to my LAN switch, which is connected in turn
10 > to another port on the vDSL modem. Once the server goes into service this
11 > interface will be down most of the time.
12
13 I have two questions:
14
15 1. Is it feasible to have both Ethernets connect, directly or indirectly,
16 to the same DSL modem/router? (Adam seemed to imply that he operates this
17 way). The device is a Billion Bipac 8900AX R2, which can segregate LAN
18 ports, but as far as I can see it can't assign different IP addresses to
19 them.
20
21 2. How should I set up routing on the web server so that outgoing traffic
22 from itself is routed as follows:
23
24 (i) if the destination is in the 192.168.1.0/24 subnet, the packet should
25 go out through enp2s0, and
26 (ii) traffic to all other destinations goes out through enp1s0?
27
28 There ought to be a simple addition to /etc/conf.d/net, but I can't see
29 what, even after looking through several web resources, including these:
30
31 https://wiki.gentoo.org/wiki/Handbook:AMD64/Networking/Introduction et seq
32 https://wiki.gentoo.org/wiki/Static_Routing.
33
34 --
35 Regards
36 Peter

Replies

Subject Author
Re: [gentoo-user] Setting up shorewall Adam Carter <adamcarter3@×××××.com>