I have a single unit environment and don't have the balls to update on the same day anymore. How is it going for the rest of you?
This thread was automatically locked due to age.
Well, I finally got support from Astaro and got as far as resolving the issue with connecting to the VM in the DMZ from within the LAN. Some kind fo policy route was interfering (a policy route that was required and didn't interfere before the update, btw).
However, we still don't have outbound connectivity from anything in the DMZ to the outside world. We were trying to use a second external (pppoe) interface with additionally assigned addresses, but that totally didn't work.
Then I tried using one of the spare IP addresses off my primary external interface (and default GW) with no success. I cannot do something as simple as ping outbound from the boxes in the DMZ, nor can I connect to them via SSH.
I have tried all manner of policy routes, static routes, checked the gateways on the servers in the DMZ, nothing seems to work.
And TRULY weird is the routing we see on a traceroute.
I have a our Primary interface on a Cable Modem from ISP #1 - labelled "External"
Our secondary interface on a PPPOE DSL connection from ISP #2 - labelled "External2"
If I tracert to an IP address on External2 interface (ISP #2) , the final visible step in the traceroute is the primary External interface's IP address (off ISP #1). It's like the ASG is somehow confusing the routing internally and trying to reply/route back out through the primary gateway. Any ideas on what we can do to fix this?
-Natalie
Bruce,
You might be on to something. I've had no success upgrading to v7.100 and my homegrown firewall uses two "Intel Corporation 82557/8/9 [Ethernet Pro 100]" NICs (1).
I'll try another rebuild in a day or two and post the results.
BillK
1. Taken from Astaro's v7.011's Network >> Interfaces >> Hardware tab.
I'm going to wait until v7.104 loads, but if all goes well I plan to return the two new Netgear NICs I recently purchased.