NetFilter
[Top] [All Lists]

Re: Bridge Transparent Proxy

To: Mail List - Netfilter <netfilter@lists.netfilter.org>
Subject: Re: Bridge Transparent Proxy
From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Date: Wed, 23 May 2007 00:07:43 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <46533B98.9030706@riverviewtech.net>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Plouf !
References: <C2787F66.1C272%robert@leblancnet.us> <465336C4.5060600@riverviewtech.net> <46533842.9080404@plouf.fr.eu.org> <46533B98.9030706@riverviewtech.net>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mozilla Thunderbird 1.0.6 (Windows/20050716)
Grant Taylor a écrit :

Let me re-layout the network including IP addresses.

(INet [A.B.C.Z]) --- (BRouter [A.B.C.D]) --- ([A.B.C.E] Server(s)
                       [192.168.144.254] --- ([192.168.144.1-100])

Here you can see that you have the same subnet of A.B.C.x on both sides of the bridging router.

Now I see. But wouldn't it be worth subnetting A.B.C.x ?

There is no good (read easy) way to have the same subnet on multiple sides of a router

Do you mean that ARP proxy would not be a good way ? Ok, I guess it would disrupt IP broadcasts a bit...

short of double natting which in and of its self is not easy to do on a singular box.

Anyway NAT is evil. Don't use unless you can't avoid it.


<Prev in Thread] Current Thread [Next in Thread>