grazman: Thanks for taking the time to respond.
Re: I am not going to debate your putting the IP's on different interfaces versus adding them as virtual ip's. You probably have your reason for doing this.
–-
Well, yes ... unfortunately that reason would politely be called "lack of understanding." <;-} I never thought of it as being a problem and, since it always worked, was happy in my ignorance.
I'll read up on VIPs and see what I can figure out.
If you'd like to make a suggestion, I'd also likely benefit from that. 'Though I do have a second test setup, the only way I can really test a config (i.e., using the direct-to-ISP equipment) is via a live router which, if it doesn't work, causes downtime.
The setup (I thought) was relatively simple:
we have multiple static IPs (allocated on the same subnet)
there's one static IP per domain name
automatic outbound NAT is set
all domains are (NAT) port-forwarded (http, https, smtp) to a specific IP where that IP is actually an IP alias with all aliases on one physical server
currently, the LAN is routed by each server (alias) IP to the applicable WAN/Opt interface (even 'though they all end up via the same ISP route)
Other than some other specific blocking by IPs, that's really all there is to it, currently.
I suspect your analysis of the "can't allocate llinfo" msgs cause is correct and is at the ISP's end. Unfortunately, our ISP (Telus) is terrible so I generally get no help from them. Fortunately we will have an alternative available prior to the end of the year and we'll switch (we use them at another office and they're good). Hopefully either a different configuration will eliminate the messages or they'll be innocuous.
Regardless, thanks for you help on this.