Is it a problem that it is dropping these ? I tried option a .. it did not seem to change anything.
It won't be a problem if you are dropping them. It's just that your firewall will generate extra packets (those redirects). The remote host can opt to ignore them (as well as there's option to disable sending redirects, there's option to disable accepting them).
Anyhow, if eth0 and eth1 are on the same wire, you are probably seeing some martians in your internal firewall logs anyhow. So you should be used to having extra stuff in logs anyhow ;-)
-- Aleksandar Milivojevic <amilivojevic@xxxxxx> Pollard Banknote Limited Systems Administrator 1499 Buffalo Place Tel: (204) 474-2323 ext 276 Winnipeg, MB R3T 1L7