Wireless bridge routing problem



Hi

We have a strange routing / firewalling problem involving a wireless
bridge.
We connected a computer (call it PC1) to our firewall (interface eth4)
using a cross-over cable. The firewall is connected to two other
networks as well: the DMZ on eth1 and our internal network on eth0. It
runs iptables and also does some source-based routing which I don't
think is relevant.

In the above configuration, PC1 can ping any machine on the DMZ and our
internal network as well as eth0 and eth1 themselves.

The moment we replace the cable with a wireless bridge (two AP's in
point-to-point mode), PC1 can no longer reach the other networks
connected to the firewall. It can however still ping eth0 and eth1.

If I ping PC2 (located on the DMZ) from PC1 the icmp packets reach eth4
according to tcpdump. That is the last time I can see the packet. It is
definitely never sent out on eth1 as expected.

I can however fix the problem by going to PC2 and pinging PC1. This is
successful and also causes the ping requests from PC1 to be passed on
to PC2. From that point on, everything works untill the firewall is
restarted. I also have to do this for each machine I want to reach from
PC1.

I suspect that the problem lies with ARP requests and the neighbor
tables on the firewall not being updated, but I cannot see problems.
How dow I solve this?

Any help will be appreciated.

.



Relevant Pages

  • dhcp question? anyone...
    ... I have two networks: ... 192.168.33.0/24 on eth1 ... 192.168.20.0/24 on eth2 ... a firewall which seperates the traffic but no IP are being assigned ...
    (comp.os.linux.misc)
  • dhcp question? anyone?
    ... I have two networks: ... 192.168.33.0/24 on eth1 ... 192.168.20.0/24 on eth2 ... a firewall which seperates the traffic but no IP are being assigned ...
    (comp.os.linux.networking)
  • Re: Do I really NEED a firewall??
    ... I've seen systems beeing broken into before they are finished ... My experience is mostly from relatively open university networks, ... because in most cases there are no central firewall. ... as you are smart enough to stay up to date with security patches, ...
    (comp.security.firewalls)
  • Re: Networking problems
    ... SP2 automatically enables the Windows Firewall. ... go to the Windows Firewall applet in Control ... File and Printer Sharing for Microsoft Networks ... Elephant Boy Computers ...
    (microsoft.public.windowsxp.network_web)
  • Re: network / nat / port forward -- problem
    ... Note that while Windows calls it connection sharing that is a windows ... from the machine connected to eth1 I could play ... I will guess that your iptables rules are routing packets from eth1 to ... Obviously your firewall rules are blocking the routed packets. ...
    (Debian-User)