Re: changing ethernet devices, new one stops cold at iptables

From: Gene Heskett
Date: Sun Jul 25 2004 - 15:32:18 EST


On Sunday 25 July 2004 05:50, Henrik Nordstrom wrote:
>On Thu, 22 Jul 2004, Gene Heskett wrote:
>> I can ping the firewall, and I can ssh into it, so that part of
>> the network is fine, I just cannot get past iptables in the
>> firewall when eth0 is the nforce hardware, which has a different
>> MAC address.
>
>Have you verified that the routing got correctly set up on the new
> box?
>
> ip ro ls
>
>The usual cause to the symptoms you describe is that the default
> route has gone missing or is invalid.

The routing was good, showing the fireall as the default gateway
address.

In this case, the fix was to reboot the firewall so that its arp
tables got refreshed to match the new MAC address of the onboard
nforce (forcedeth) nic. Once that was done, everything was peachy.

Thanks, I appreciate the reply, Henrik.

--
Cheers, Gene
There are 4 boxes to be used in defense of liberty.
Soap, ballot, jury, and ammo.
Please use in that order, starting now. -Ed Howdershelt, Author
Additions to this message made by Gene Heskett are Copyright 2004,
Maurice E. Heskett, all rights reserved.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/