NetFilter
[Top] [All Lists]

Re: Bridge Transparent Proxy

To: Mail List - Netfilter <netfilter@lists.netfilter.org>
Subject: Re: Bridge Transparent Proxy
From: Grant Taylor <gtaylor@riverviewtech.net>
Date: Tue, 22 May 2007 11:09:28 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <C2785BE6.1C244%robert@leblancnet.us>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Riverview Technologies Inc.
References: <C2785BE6.1C244%robert@leblancnet.us>
Reply-to: gtaylor+reply@riverviewtech.net
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.3) Gecko/20070511 Thunderbird/2.0.0.0 Mnenhy/0.7.5.666
On 05/22/07 09:35, Robert LeBlanc wrote:
You will need to look at ebtables. Bridging will bypass iptables. Ebtables
is much like iptables, but there are some subtle differences that may choke
you up. Haven't worked much with it though.

You can configure the kernel to apply IPTables Net Filters (Layer 3) to EBTables bridged (Layer 2) traffic.

To quote the (2.6.8.1) kernel source:
"""
CONFIG_BRIDGE_NETFILTER - Enabling this option will let arptables resp. iptables see bridged ARP resp. IP traffic. If you want a bridging firewall, you probably want this option enabled.

Enabling or disabling this option doesn't enable or disable ebtables.
"""




Grant. . . .


<Prev in Thread] Current Thread [Next in Thread>