# routing 2 internal LANS

**URL:** <https://forums.suse.com/t/routing-2-internal-lans/23085>\
**Category:** SLES Networking\
**Created:** [September 12, 2012, 8:28pm UTC](https://forums.suse.com/t/routing-2-internal-lans/23085 "2012-09-12T20:28:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![System1](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@System1](https://forums.suse.com/u/System1)\
**Post date:** [September 12, 2012, 8:28pm UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/1 "2012-09-12T20:28:33Z")

</div>

we are moving from NetWare to OES2  
I have setup the SLES 11 server that we are going to be using and I am  
slowly moving services over to it.

our old NW server routed traffic between two network and I need the new  
SLES 11 server to do the same thing.

eth0 = 10.0.1.21  
eth1 = 10.0.2.21

(following various bits of information I’ve gathered searching google)  
I made the following changes in /etc/sysconfig/SuSEfirewall2  
FW\_DEV\_EXT=“any eth0”  
FW\_DEV\_INT=“eth1”  
FW\_ROUTE=“yes”  
FW\_MASQUERADE=“yes”  
FW\_MASQ\_DEV=“zone:ext”  
FW\_MASQ\_NETS=“0/0”

so…  
devices connected to eth1 can connect to everything on eth0.  
devices connected to eth0 cannot connect to anything on eth1.  
and that seems to make sense - this looks like a typical firewall setup,  
let traffic from eth1 masquerade to eth0.

I’m not sure if I messed up a setting or went in the complete wrong  
direction. Is there a simpler way to route 2 networks without using  
masquerade?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [September 12, 2012, 10:31pm UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/2 "2012-09-12T22:31:19Z")

</div>

I got it working

it was missing the FW\_FORWARD=“10.0.1.0/24,10.0.2.0/24”

still curious if this the right way to do this

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [September 13, 2012, 3:26am UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/3 "2012-09-13T03:26:58Z")

</div>

Steve B wrote:  
[color=blue]

> I’m not sure if I messed up a setting or went in the complete wrong  
> direction. Is there a simpler way to route 2 networks without using  
> masquerade?[/color]

Yes! /etc/sysconfig/SuSEfirewall2 is the correct place to make the  
configuration changes but what are you trying to do?

FW\_ROUTE=“yes”  
FW\_FORWARD=“10.0.1.21/24,10.0.2.21/24 10.0.2.21/24,10.0.1.21/24”

Is that what you _really_ want?

You said:  
[color=blue]

> eth0 = 10.0.1.21  
> eth1 = 10.0.2.21
> 
> FW\_DEV\_EXT=“any eth0”  
> FW\_DEV\_INT=“eth1”[/color]

You would be permitting _all_ traffic between your external and private  
networks. Essentially, you would have no firewall.

FW\_FORWARD allows you to be very specific about what is to be  
forwarded. Read the comments in /etc/sysconfig/SuSEfirewall2 and be  
very sure about what you are trying to accomplish.

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are using the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [September 13, 2012, 4:15am UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/4 "2012-09-13T04:15:58Z")

</div>

On 9/12/12 7:26 PM, KBOYLE wrote:[color=blue]

> Steve B wrote:  
> [color=green]
> 
> > I’m not sure if I messed up a setting or went in the complete wrong  
> > direction. Is there a simpler way to route 2 networks without using  
> > masquerade?[/color]
> 
> Yes! /etc/sysconfig/SuSEfirewall2 is the correct place to make the  
> configuration changes but what are you trying to do?
> 
> FW\_ROUTE=“yes”  
> FW\_FORWARD=“10.0.1.21/24,10.0.2.21/24 10.0.2.21/24,10.0.1.21/24”
> 
> Is that what you _really_ want?
> 
> You said:  
> [color=green]
> 
> > eth0 = 10.0.1.21  
> > eth1 = 10.0.2.21
> > 
> > FW\_DEV\_EXT=“any eth0”  
> > FW\_DEV\_INT=“eth1”[/color]
> 
> You would be permitting _all_ traffic between your external and private  
> networks. Essentially, you would have no firewall.
> 
> FW\_FORWARD allows you to be very specific about what is to be  
> forwarded. Read the comments in /etc/sysconfig/SuSEfirewall2 and be  
> very sure about what you are trying to accomplish.  
> [/color]

these are internal networks that need to talk to each other - not  
hitting the internet.

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [September 13, 2012, 5:28am UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/5 "2012-09-13T05:28:08Z")

</div>

Steve B wrote:  
[color=blue]

> these are internal networks that need to talk to each other - not  
> hitting the internet.[/color]

That should work then. You’ll want IP forwarding on. You can enable it  
for each nic in the YaST network configuration.

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are using the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [September 13, 2012, 5:56am UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/6 "2012-09-13T05:56:52Z")

</div>

On 9/12/12 9:28 PM, KBOYLE wrote:[color=blue]

> Steve B wrote:  
> [color=green]
> 
> > these are internal networks that need to talk to each other - not  
> > hitting the internet.[/color]
> 
> That should work then. You’ll want IP forwarding on. You can enable it  
> for each nic in the YaST network configuration.  
> [/color]  
> Thanks

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [September 13, 2012, 9:02am UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/7 "2012-09-13T09:02:30Z")

</div>

KBOYLE wrote:  
[color=blue]

> FW\_FORWARD=“10.0.1.21/24,10.0.2.21/24 10.0.2.21/24,10.0.1.21/24”[/color]

Sorry for the typo…

FW\_FORWARD=“10.0.1.0/24,10.0.2.0/24 10.0.2.0/24,10.0.1.0/24”

It should read: from subnet 1 to subnet 2 and from subnet 2 to subnet 1.

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are using the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![Simeonof](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Simeonof](https://forums.suse.com/u/Simeonof)\
**Post date:** [September 17, 2012, 1:02pm UTC](https://forums.suse.com/t/routing-2-internal-lans/23085/8 "2012-09-17T13:02:20Z")

</div>

You may also have a look at [www.fwbuilder.org](http://www.fwbuilder.org) - makes life a lot easier when it comes to routing/firewall configuration. Way better than SuSEfirewall (IMHO) .

[QUOTE=Steve B;6837]I got it working

it was missing the FW\_FORWARD=“10.0.1.0/24,10.0.2.0/24”

still curious if this the right way to do this[/QUOTE]
