On Sun, 2003-11-02 at 13:39, Tom Eastep wrote: > Such a setup is pure "security by obscurity" since the firewall can be > bypassed by hosts on your external subnet. Having both interfaces > connected to the same HUB/switch also means that either interface can > answer ARP "who-has" requests for addresses assigned to either > interface. That's why you see the "wrong" interface accepting input > traffic. > OK. I reconfigured and pulled the plug on eth1 to the router. Let's see what happens.
Attachment:
signature.asc
Description: This is a digitally signed message part