Linux Routing Firewall Help please !!

Posted on 2007-04-05
Last Modified: 2013-12-16
I am trying to configure a firewall with 2 nics.

eth0      Link encap:Ethernet  HWaddr 00:15:E9:FA:43:6E
          inet addr:  Bcast:  Mask:
          RX packets:6127 errors:0 dropped:0 overruns:0 frame:0
          TX packets:5583 errors:0 dropped:0 overruns:0 carrier:0
          collisions:44 txqueuelen:100
          RX bytes:3368292 (3.2 Mb)  TX bytes:725801 (708.7 Kb)
          Interrupt:11 Base address:0xd000
eth1      Link encap:Ethernet  HWaddr 00:04:5A:7A:E4:48
          inet addr:  Bcast:  Mask:
          RX packets:3408 errors:0 dropped:0 overruns:0 frame:0
          TX packets:737 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:334099 (326.2 Kb)  TX bytes:53127 (51.8 Kb)
          Interrupt:10 Base address:0x5c00
lo        Link encap:Local Loopback
          inet addr:  Mask:
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:22347 errors:0 dropped:0 overruns:0 frame:0
          TX packets:22347 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:1528193 (1.4 Mb)  TX bytes:1528193 (1.4 Mb)

if I disable eth1 then I can access the internet and ping works all the way around. But when I enable eth1 for the internal network I get the following

[root@firewall root]# ping
PING ( 56(84) bytes of data.
64 bytes from icmp_seq=1 ttl=64 time=0.039 ms
[root@firewall root]# ping
PING ( 56(84) bytes of data.
64 bytes from icmp_seq=1 ttl=255 time=0.818 ms
[root@firewall root]# ping
PING ( 56(84) bytes of data.
From icmp_seq=1 Destination Host Unreachable
[root@firewall root]# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface U     0      0        0 eth0   U     0      0        0 eth1     U     0      0        0 eth1       U     0      0        0 lo         UG    0      0        0 eth1

According to the documentation I have read this set up should work and I am at a loss for what to do next.
Any idea's?  
Question by:MarkWP

Accepted Solution

cheesygit182 earned 500 total points
ID: 18861271
"inet addr:  Bcast:  Mask:"
That's your problem. Your usage of the kernels routing tables is perfect, but one of the NICs isn't configured correctly. Test them individually and paste the results of ifconfig here, for each.


Author Comment

ID: 18861500
I had a gateway entered on both nics

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
nagios remote hosts 9 56
Run DOS2UNIX and then execute the command 21 71
how to install java on RHEL image on EC2 4 28
winscp 6 54
How many times have you wanted to quickly do the same thing to a list but found yourself typing it again and again? I first figured out a small time saver with the up arrow to recall the last command but that can only get you so far if you have a bi…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (, affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question