On Thursday 30 May 2002 00:10, Jorge# ./S wrote:
> Any ebtables expert can help us solve this:
>
> Can GRE packets be forwarded on a linux box using ebtables?
>
> ----------  Forwarded Message  ----------
>
> Subject: Re: I can't vpn ! - ebtables can forward GRE?
> Date: Thu, 30 May 2002 00:09:11 +0100
> From: Antony Stone <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
>
> On Wednesday 29 May 2002 11:00 pm, Jorge Sarmiento wrote:
> > With ebtables you can block protocols that are not TCP, and let pass TCP,
> > ICMP and UDP to your network... you can also redirect TCP packets to do
> > an "invisible transparent proxy", mixing bridging and ebtables... then
> > why couldn't GRE packets be forwarded??

If you know the protocol number of these GRE packets you can filter on the 
protocol number. ebtables -p IPv4 --ip-protocol 47. There is only support for 
ip header filtering. E.g. no TCP port filtering, certainly no GRE specific 
filtering. These things belong in iptables.
With ebtables you can only change the MAC source and destination address. A 
redirect in ebtables only means the MAC destination of the frame is changed 
to that of the bridge, causing the frame to be routed or delivered to the 
bridge itself. You can also make a brouter with ebtables. IP redirects 
obviously belong in iptables.
I'm not subscribed to the netfilter users list. For ebtables questions there 
is a mailing list too. See the ebtables hp.

cheers,
Bart


Reply via email to