[CentOS] Not firewall, but what?

Sat May 8 06:01:33 UTC 2010
Gordon Messmer <yinyang at eburg.com>

On 05/07/2010 07:26 AM, Jussi Hirvi wrote:
> [root at farm1 log]# ip route show
> dev eth0  proto kernel  scope link  src
> dev eth1  proto kernel  scope link  src
> dev virbr0  proto kernel  scope link  src
> dev eth1  scope link
> default via dev eth1

Yeah, so you have two interfaces on different IP networks.  When someone 
connects to, the reply packets will still head out through on eth1.  That router probably filters the reply packets 
since they're from a non-local IP network.

I'm not sure if there's a simpler way to do this:  When I have 
multi-homed servers I usually just use Shorewall to create two routing 
tables: one with a default route through each outbound router.  Packets 
are marked based on their source address and routed based on those marks.