# Basic help on getting SLES to route

**URL:** <https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374>\
**Category:** SLES Networking\
**Created:** [December 4, 2012, 10:26am UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374 "2012-12-04T10:26:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rough\_diamond](https://avatars.discourse-cdn.com/v4/letter/r/ad7895/32.png) [@rough\_diamond](https://forums.suse.com/u/rough_diamond)\
**Post date:** [December 4, 2012, 10:26am UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/1 "2012-12-04T10:26:12Z")

</div>

Hi - I have seen various posts related to this topic but none really give a step by step guide so hopefully someone out there can fill in the blanks  
We would like to set up a SLES 10.3 server to be able to route packets between different subnets  
For example subnet 192.168.0.0 /24 will be able to route to 10.0.0.0 /8 - This server will not have any connections to the the internet.  
eth0 = 192.168.0.1  
eth1 = 10.0.0.1

I have enabled ip-forwarding on the SLES box and can ping from a separate device on the 192.168.0.0 network throught to eth1 on 10.0.0.1 but I cannot ping any devices beyond that interface on the 10.0.0.0 network.

From reading the board I suspect this may be firewall related but I am not sure how to resolve the issue.

Any help would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [December 4, 2012, 1:40pm UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/2 "2012-12-04T13:40:50Z")

</div>

Am 04.12.2012 09:34, schrieb rough diamond:[color=blue]

> I have enabled ip-forwarding on the SLES box and can ping from a  
> separate device on the 192.168.0.0 network throught to eth1 on 10.0.0.1[/color]

AFAIR this would always work, the SLES routes internally to the second  
NIC without further configuration.  
[color=blue]

> but I cannot ping any devices beyond that interface on the 10.0.0.0  
> network.[/color]

You have to setup a route to the 10.0.0.0 net.

What is the output from?

# route

Tom

---

<div class="post-metadata">

**Author:** ![rough\_diamond](https://avatars.discourse-cdn.com/v4/letter/r/ad7895/32.png) [@rough\_diamond](https://forums.suse.com/u/rough_diamond)\
**Post date:** [December 4, 2012, 3:04pm UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/3 "2012-12-04T15:04:01Z")

</div>

Thanks for the reply Tom  
In the meantime I managed to ping devices on 10.0.0.x from 192.168.0.x by editing the /etc/sysconfigSuSEfirewall2 - In the FW\_FORWARD= section I added the two subnets  
is this what you meant by add the route or were you refering to  
adding a static route? I would be interested to know the answer. Doing a netstat -r shows a route to the 10.0.0.0 network as this is associated with the interface with the IP of 10.0.0.1  
Destination Gateway Genmask Flags Metric Ref Use Iface  
10.0.0.0 \* 255.255.255.0 U 0 0 0 eth7

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [December 4, 2012, 3:39pm UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/4 "2012-12-04T15:39:19Z")

</div>

> is this what you meant by add the route or were you refering to[color=blue]  
> adding a static route? I would be interested to know the answer. Doing[/color]

No, I meant ‘route add net…’  
But there’s no need to because the route exists, as your ping after  
adding the fw-rules shows

Tom

---

<div class="post-metadata">

**Author:** ![rough\_diamond](https://avatars.discourse-cdn.com/v4/letter/r/ad7895/32.png) [@rough\_diamond](https://forums.suse.com/u/rough_diamond)\
**Post date:** [December 4, 2012, 3:47pm UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/5 "2012-12-04T15:47:00Z")

</div>

Thanks Tom

Everything looks good now- thanks for the replies

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [December 4, 2012, 8:51pm UTC](https://forums.suse.com/t/basic-help-on-getting-sles-to-route/23374/6 "2012-12-04T20:51:36Z")

</div>

rough diamond wrote:  
[color=blue]

> Everything looks good now- thanks for the replies[/color]

I see you got this resolved. That’s great.

When IP Forwarding is not enabled, devices on either subnet should be  
able to access either interface on your server but none of the devices  
on the other subnet. Once you enable IP Forwarding, you still have to  
specify what traffic is to be forwarded. It’s not a case of all or  
nothing.

Just for reference, this discussion began here:  
[http://forums.suse.com/showthread.php?t=2097](http://forums.suse.com/showthread.php?t=2097)

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are using the web interface,  
show your appreciation and click on the star below…
