Mailinglist Archive: opensuse-security (465 mails)

< Previous Next >
RE: [suse-security] proxy-arp problems ...
  • From: "Reckhard, Tobias" <tobias.reckhard@xxxxxxxxxxx>
  • Date: Fri, 7 Dec 2001 10:53:10 +0100
  • Message-id: <96C102324EF9D411A49500306E06C8D1A56C91@xxxxxxxxxxxxxxxxx>
> My guess is that proxy_arp is the wrong tool then.
> Try adding additional IPs to the Interface of the Firewall.
> For example try:
> "ip add dev eth0"
> Package: iproute2 (SuSE 7.2)
> then your FW answers the arp-requests (I think so).
> Deactivate proxy_arp.

This is true, Ray doesn't want proxy-arp, he wants the firewall to answer
arps on behalf of the public servers behind it. My mistake in introducing
the term 'proxy-arp' in the first place, I probably hadn't given it enough
thought or been confused and assumed that the public servers actually used
their public IP addresses. Sorry for the confusion created.


< Previous Next >
Follow Ups