Subnet, gateway and iptables question

From: B (
Date: 02/07/02

From: (B)
Date: 7 Feb 2002 06:25:45 -0800


The situation is this, I have one real firewall setup which works
fine. Its connected to the internet through a lease line. I then split
the incoming line into 2 and connected another test firewall machine.
I gave this test firewall a test lan to protect. I then setup my
firewall ruleset to allow ssh connections to the test firewall and the
test lan machine. The firewall rules also dnatted 124.XX.XX.XX (one of
my free external IPs) to the internal address of the lan machine.

I had problems with this as I couldnt connect to the lan machine using
the external 124.xx.xx.xx address(i was trying to connect from a
machine on the real lan behind the real firewall). All I was getting
was arp-request who has 124.xx.xx.xx from the real firewall machine.

I then subnetted my test firewall onto a different network than the
real firewall and setup the routing table in the real firewall to
point to this new subnet with the test firewall as the gateway. Since
then all has gone according to plan.

Can anyone explain why this is so. If i hadnt subnetted the test
firewall and left both firewall machines on the same network, just
changing the routing table on the real firewall to say that the test
firewall was a gateway to its own network would everything have worked
that way?


