Discussion:
[Shorewall-users] VLAN as provider
Göran Höglund
2017-06-15 13:46:20 UTC
Permalink
Hi,
Is there anyone who can give a hint of the best practise for tagged VLAN
interfaces used in shorewall/providers???
Lets say I have a VLAN trunk interface eth2 and want to have two VLANs
to two different ISP's eth2.2 and eth2.3

rules for the total interface including both VLANs are as I understand
it tied to the trunk eth2 defined in the zone file
but how do I configure providers?

regads
/Göran
Tom Eastep
2017-06-15 14:58:05 UTC
Permalink
Hi, Is there anyone who can give a hint of the best practise for
tagged VLAN interfaces used in shorewall/providers??? Lets say I
have a VLAN trunk interface eth2 and want to have two VLANs to two
different ISP's eth2.2 and eth2.3
rules for the total interface including both VLANs are as I
understand it tied to the trunk eth2 defined in the zone file but
how do I configure providers?
The only interfaces in your configuration will be eth2.2 and eth2.3,
both for rules and for providers.

- -Tom
- --
Tom Eastep \ Q: What do you get when you cross a mobster with
Shoreline, \ an international standard?
Washington, USA \ A: Someone who makes you an offer you can't
http://shorewall.org \ understand
\_______________________________________________
Göran Höglund
2017-06-16 09:26:10 UTC
Permalink
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hi, Is there anyone who can give a hint of the best practise for
tagged VLAN interfaces used in shorewall/providers??? Lets say I
have a VLAN trunk interface eth2 and want to have two VLANs to two
different ISP's eth2.2 and eth2.3
rules for the total interface including both VLANs are as I
understand it tied to the trunk eth2 defined in the zone file but
how do I configure providers?
The only interfaces in your configuration will be eth2.2 and eth2.3,
both for rules and for providers.
- -Tom
- --
Tom Eastep \ Q: What do you get when you cross a mobster with
Shoreline, \ an international standard?
Washington, USA \ A: Someone who makes you an offer you can't
http://shorewall.org \ understand
\_______________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: GPGTools - http://gpgtools.org
iQIcBAEBCAAGBQJZQqB8AAoJEJbms/JCOk0QiZYP/RNujQb1a8CM8Xru3aTmWJAg
ZVGPEFsFHtLY7lBbFxxmhMjwh6CDbTMWc2jsSijYpjSfACk1ch/wqH1NCSbFw425
fCYpSBI2Qgm6WAMOp9qaOkTzexWZR4WPy6RQMYq39FRIJEXiTHyFE6dmrusPd3Bt
dh/NYR0GZr57RaqpVmImgGiF+dhb0AvCeQ5ti+vbkdoeM5JMx7KFo2UxJuW7JtBE
5BEbsDRER/bNfwD5lJLsX6hPvuz0HfkjRf52VYs5y5yLghgw+xH4QFwip8n1pOsR
ndJaNZn9VD0ETOqoGgUgnMOQkl4yo408Ps036w0LBuPsjjLzve2qQkzTmB4NQ7PI
KBdFx5bflGOJLWt9o9ft/S6UXFpI6+O2kq7VY6n/r0TX5p5zQ6KMwHsCxfkkC2Je
D7l/z2HkOrJhLJ0H6nly7R/jfRtjX+AjJMJUsQZT6hp/+L0LAaUhYLFIr5TZQ3wI
PmXALnRW/vxyiJ6gAHA3tJYP6iK6pttRlBq/c3uPJXOCV+/OYNGhPF22UmSfAtc/
vFCHUUEGsYU7b+jfGmZnEPEbe5alTlSy7DDD1UnQ1Ru5uf6QqUA06/jrusAaTqmV
pp4g0vsq3RSmW962/Moy9mhJQGyzf+7lOB4RE9LWltIe2kUA3mN6cJYN5DiUwlCT
ceng1jJ/ZA0g9OplqXT/
=xrKi
-----END PGP SIGNATURE-----
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Shorewall-users mailing list
https://lists.sourceforge.net/lists/listinfo/shorewall-users
Just to be sure, nothing needed in interfaces and zones??
Not even the "base" interface eth2?

Thanks for above answer!

/Göran
Tom Eastep
2017-06-16 15:22:11 UTC
Permalink
Just to be sure, nothing needed in interfaces and zones?? Not even
the "base" interface eth2?
The VLAN interfaces must appear in the interfaces file -- the base
interface eth2 does not.

- -Tom
- --
Tom Eastep \ Q: What do you get when you cross a mobster with
Shoreline, \ an international standard?
Washington, USA \ A: Someone who makes you an offer you can't
http://shorewall.org \ understand
\_______________________________________________

Loading...