<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=utf-8">
<META NAME="Generator" CONTENT="MS Exchange Server version 6.5.7652.24">
<TITLE>Re: [CentOS] Re: Network routes</TITLE>
</HEAD>
<BODY>
<!-- Converted from text/plain format -->
<BR>
<P><FONT SIZE=2>Sorry for the top post.<BR>
<BR>
The default route is the route applied when no other route matches the destination IP. From that how would you figure out which default route to pick, only if the routes were weighted could you pick between two.<BR>
<BR>
If you had two routes with equal weight and the traffic went round robin between them then the originating host will discard half the returning traffic because it's not coming from the same ip it sent it to.<BR>
<BR>
No your best bet is probably to do reverse NAT'ing as it is simple to setup and you don't have to worry about default routes and weight. Traffic initiates on 1 gateway and sticks with it for the duration of the session. You can use BGP on the gateways outside interface to load balance or fail-over the default gateway or use round-robin DNS, MX records for mail, etc.<BR>
<BR>
-Ross<BR>
<BR>
<BR>
----- Original Message -----<BR>
From: centos-bounces@centos.org <centos-bounces@centos.org><BR>
To: centos@centos.org <centos@centos.org><BR>
Sent: Tue Jan 29 18:03:13 2008<BR>
Subject: [CentOS] Re: Network routes<BR>
<BR>
on 1/29/2008 2:53 PM Jason Pyeron spake the following:<BR>
> <BR>
><BR>
>> -----Original Message-----<BR>
>> From: centos-bounces@centos.org<BR>
>> [<A HREF="mailto:centos-bounces@centos.org">mailto:centos-bounces@centos.org</A>] On Behalf Of Ross S. W. Walker<BR>
>> Sent: Tuesday, January 29, 2008 17:38<BR>
>> To: CentOS mailing list<BR>
>> Subject: RE: [CentOS] Network routes<BR>
>><BR>
>> Jason Pyeron wrote:<BR>
>>> I am unable to ping NE.TW.RKB.IP1 from an outside network.<BR>
>>> Other machines<BR>
>>> which do not have access or routes for NET.WOR.KA.0 respond<BR>
>> just fine.<BR>
>>> How do I get it to respond on both NET.WOR.KA.0 and<BR>
>>> NE.TW.RKB.0 given all<BR>
>>> default traffic should go through NET.WOR.KA.1 unless it is<BR>
>>> in reply to<BR>
>>> traffic from NE.TW.RKB.1 or there is an outage.<BR>
>>><BR>
>>> [root@host20 ~]# route -n<BR>
>>> Kernel IP routing table<BR>
>>> Destination Gateway Genmask Flags Metric<BR>
>>> Ref Use<BR>
>>> Iface<BR>
>>> NET.WOR.KA.0 0.0.0.0 255.255.255.0 U 0 <BR>
>>> 0 0 eth1<BR>
>>> 192.168.1.0 0.0.0.0 255.255.255.0 U 0 <BR>
>>> 0 0 eth0<BR>
>>> NE.TW.RKB.0 0.0.0.0 255.255.255.0 U 0 <BR>
>>> 0 0 eth0<BR>
>>> 169.254.0.0 0.0.0.0 255.255.0.0 U 0 <BR>
>>> 0 0 eth1<BR>
>>> 0.0.0.0 NET.WOR.KA.1 0.0.0.0 UG 0 <BR>
>>> 0 0 eth1<BR>
>>> 0.0.0.0 NE.TW.RKB.1 0.0.0.0 UG 20 <BR>
>>> 0 0 eth0<BR>
>>><BR>
>>> [root@host20 ~]# ifconfig<BR>
>>> eth0 Link encap:Ethernet HWaddr 00:17:31:0F:04:AE<BR>
>>> inet addr:NE.TW.RKB.IP1 Bcast:NE.TW.RKB.255 <BR>
>>> Mask:255.255.255.0<BR>
>>> eth0:pn Link encap:Ethernet HWaddr 00:17:31:0F:04:AE<BR>
>>> inet addr:192.168.1.20 Bcast:192.168.1.255 <BR>
>>> Mask:255.255.255.0<BR>
>>> eth1 Link encap:Ethernet HWaddr 00:01:03:E9:42:D0<BR>
>>> inet addr:NET.WOR.KA.IP2 Bcast:NET.WOR.KA.255 <BR>
>>> Mask:255.255.255.0<BR>
>>> lo Link encap:Local Loopback<BR>
>>> inet addr:127.0.0.1 Mask:255.0.0.0<BR>
>>><BR>
>> You can have only 1 default route.<BR>
>><BR>
>> You can use RIP or some other routing protocol to<BR>
>> advertise defualt routes to the host from the<BR>
>> gateways based upon route availability or weight,<BR>
>> or you can deploy reverse NAT'ing on the gateways<BR>
>> so external IPs will be masqueraded as the<BR>
>> internal IP of the gateway and thus be routed to<BR>
>> the appropriate gateway based on which IP they<BR>
>> arrived on.<BR>
>><BR>
>> -Ross<BR>
>><BR>
><BR>
> But I have 2 physical network cards, on 2 different networks. Should they<BR>
> not both have default routes?<BR>
><BR>
You would think so, but it will confuse the system so bad that traffic won't<BR>
know where to go. The default route is the route that packets need to take to<BR>
leave your network to enter the outside world. Every thing under your control<BR>
should have static routes of some kind, or a routing daemon.<BR>
<BR>
--<BR>
MailScanner is like deodorant...<BR>
You hope everybody uses it, and<BR>
you notice quickly if they don't!!!!<BR>
<BR>
</FONT>
</P>
<P></P>
<HR WIDTH="100%">
This e-mail, and any attachments thereto, is intended only for use by
the addressee(s) named herein and may contain legally privileged
and/or confidential information. If you are not the intended recipient
of this e-mail, you are hereby notified that any dissemination,
distribution or copying of this e-mail, and any attachments thereto,
is strictly prohibited. If you have received this e-mail in error,
please immediately notify the sender and permanently delete the
original and any copy or printout thereof.
</BODY>
</HTML>