intermittent network/firewall failure

acfabro_at_gmail.com
Date: 09/18/05


Date: 17 Sep 2005 23:26:12 -0700

Hi all,

I've recently tried setting up a firewall for our office and tried
shorewall/iptables on CentOS. Installation and setup was easy and
everything works fine except i've been getting intermittent network
failure. During the interruption, the firewall can't ping its gateway
(our dsl provider), although when I do a "service network reload"
everything is normal again (except when the network failure randomly
strikes again).

Now i've tried the redwall livecd fireall (i think its also
redhat-based), and the same problem comes back. When I plug the network
to our old linksys dsl router, the intermittent failure don't appear
anymore.

I want to know what's going on but I don't know where to start. You may
want to suggest that I use another distro/os/firewall but I really,
really want to know what went on in there. Any help on locating the
problem is really appreciated.

btw, this is the setup: the box has 3 nics (1 for net, local and dmz),
we have a block of 5 static ip addresses. the box is built is on a
celeron 1.7 (right, whoa!) and 256mb ram



Relevant Pages

  • Advice for SOHO firewall gear?
    ... I'm planning to expand my home/hobby network from a small gateway-server ... would like advice on firewall gear. ... Firewalled routing from perimeter network to trusted network ... traditional two-router setup is also OK, so long as the initial cost ...
    (comp.security.firewalls)
  • Re: Linux Firewall or Netgear
    ... I am currently setting up a network ... a PC running a firewall or a small appliance ... you need to pick the one you are sure you can setup based on ... 2000 Advanced Server can be setup as a VPN Server and supports simple ...
    (comp.security.firewalls)
  • Re: Linux Router
    ... > of my clients behind the firewall to see beyond the firewall. ... > My two network cards are setup as: ... > I rebooted the machine after the above network setup, ... pass out on $ext_if proto tcp all modulate state flags S/SA ...
    (Debian-User)
  • Re: VRRP on NOKIA (CheckPoint)
    ... > For the VRRP setup, do I have to take into account eth3c0's??? ... Primary FW Configure the two data networks to monitor each other. ... Once the Primary network is back up, it will preempt (to use a cisco ... hsrp term) the Secondary Firewall and become Master again (as its ...
    (comp.security.firewalls)
  • RE: can ping but not browse
    ... I have stopped the firewall. ... # are safed from all (security) hazards. ... firewall/bastion host to the internet ... # internet and to an internal network, ...
    (Fedora)