(E-Mail Removed) wrote:
> Traffic from the eth1 networks should *never* *ever* under any
> circumstances be sent over the eth0 network. That's why no
> forwarding. If I ran iptables, there would be no connections between
> the two sides. Why then does arp have to respond? -- it doesn't and
> it seems like a good thing to me that the option exists to have it
> *not*.
If the "wrong" interface is responding to ARP requests, it implies
that the wrong interface is connected to the same link-level broadcast
domain as the "right" interface. So, ipforwarding enabled or not
(that being up at layer3), unless you have vlans (which would have
precluded the wrong interface from seeing the ARP requests in the
first place) you have a situation where traffic for both IP subnets
are on the same wire, visible to anyone at layer2.
rick jones
--
denial, anger, bargaining, depression, acceptance, rebirth...
where do you want to be today?
these opinions are mine, all mine; HP might not want them anyway...

feel free to post, OR email to rick.jones2 in hp.com but NOT BOTH...