On Monday 03 December 2001 15:35, RoMaNSoFt wrote:
> On Mon, 3 Dec 2001 13:15:36 +0000, you wrote:
> >3 nics --> 2 to bridge and another to do administrations tasks
>
>  Why don't you use  any of the 2 working nics for administration
> tasks? (for instance you could assign ip to br0 device).

i can't acces trought br0.. i don't know if i do a mistake or whatelse.. but 
the sistem is working anyaway. And i think this mode is best, because i can 
leave the eths from br0 free to do they work.. bridging :-)

>
> >i am using a 2.4.13-ac5 - heavly modified kernel (bridge-nf + ebtables +
> >iptables)
>
>  If bridge-nf provides filtering, what's the advantage of ebtables
> patch?? Sorry, I'm kindda newbie at linux bridginng...

ebtables is a patch from Bart De Schuymer (i hope he is reading this ;-). You 
can get from:  

http://users.pandora.be/bart.de.schuymer/ebtables/

ebtables is looklike iptables, but it works with MAC addressess (not ip, like 
iptables) (ok, ok, iptables works with MAC too, but ebtables is very, very 
more easy to use with MACs than iptables).

iptables is excelent to do port (and ip) filtering... but i have some 
"creative" users wich swap they ips.. then i will be more creative then 
they... :-)

here when come ebtables... it is execelent to filter another protocols wich 
not be ipv4 (ipx, etc) and i can track MACs directly.

well, i think i can did this with only iptables or ebtables...but i am too 
lazy and take the easyest path ;-)

so i dot that: port filtering with iptables and protocols (and macs) 
filtering with ebtables

>
>  Salu2,
>  --Roman

ps: i (trying) work in a documentation about wath i did here.. when its done 
i will announce on this list.
ps2: first version in portuguese, so then i will translate to english.
_______________________________________________
Bridge mailing list
[EMAIL PROTECTED]
http://www.math.leidenuniv.nl/mailman/listinfo/bridge

Reply via email to