I have a single unit environment and don't have the balls to update on the same day anymore. How is it going for the rest of you?
This thread was automatically locked due to age.
Well, I finally got support from Astaro and got as far as resolving the issue with connecting to the VM in the DMZ from within the LAN. Some kind fo policy route was interfering (a policy route that was required and didn't interfere before the update, btw).
However, we still don't have outbound connectivity from anything in the DMZ to the outside world. We were trying to use a second external (pppoe) interface with additionally assigned addresses, but that totally didn't work.
Then I tried using one of the spare IP addresses off my primary external interface (and default GW) with no success. I cannot do something as simple as ping outbound from the boxes in the DMZ, nor can I connect to them via SSH.
I have tried all manner of policy routes, static routes, checked the gateways on the servers in the DMZ, nothing seems to work.
And TRULY weird is the routing we see on a traceroute.
I have a our Primary interface on a Cable Modem from ISP #1 - labelled "External"
Our secondary interface on a PPPOE DSL connection from ISP #2 - labelled "External2"
If I tracert to an IP address on External2 interface (ISP #2) , the final visible step in the traceroute is the primary External interface's IP address (off ISP #1). It's like the ASG is somehow confusing the routing internally and trying to reply/route back out through the primary gateway. Any ideas on what we can do to fix this?
-Natalie
Well, I finally got support from Astaro and got as far as resolving the issue with connecting to the VM in the DMZ from within the LAN. Some kind fo policy route was interfering (a policy route that was required and didn't interfere before the update, btw).
However, we still don't have outbound connectivity from anything in the DMZ to the outside world. We were trying to use a second external (pppoe) interface with additionally assigned addresses, but that totally didn't work.
Then I tried using one of the spare IP addresses off my primary external interface (and default GW) with no success. I cannot do something as simple as ping outbound from the boxes in the DMZ, nor can I connect to them via SSH.
I have tried all manner of policy routes, static routes, checked the gateways on the servers in the DMZ, nothing seems to work.
And TRULY weird is the routing we see on a traceroute.
I have a our Primary interface on a Cable Modem from ISP #1 - labelled "External"
Our secondary interface on a PPPOE DSL connection from ISP #2 - labelled "External2"
If I tracert to an IP address on External2 interface (ISP #2) , the final visible step in the traceroute is the primary External interface's IP address (off ISP #1). It's like the ASG is somehow confusing the routing internally and trying to reply/route back out through the primary gateway. Any ideas on what we can do to fix this?
-Natalie