Re: Limitations of Net6501 as a network bridge

Greg Troxel <[email protected]> Fri, 26 Jun 2015 08:36:34 -0400
Newsgroups gmane.comp.hardware.soekris.technical
Message-ID <[email protected]>
Jed Clear <[email protected]> writes:

> I haven't explored iptables in bridge/layer 2 mode, but there is no
> fundamental reason you can't packet sniff or firewall traffic in
> bridge mode. The traffic has to pass through your kernel.

I don't know about iptables, but ipfilter in NetBSD can do filtering by
matching on IP headers for bridges.

With snort, you should be able to pick any of the bridged interfaces,
but once you start firewalling you probably want the WAN-facing one.

_______________________________________________
Soekris-tech mailing list
[email protected]
http://lists.soekris.com/mailman/listinfo/soekris-tech
signature.asc (application/pgp-signature, 180 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iEYEARECAAYFAlWNR1IACgkQH9p66AmO1g6mIACePGUvSE+U4wCrGHL3VhfLl+Nc
wDoAnjPP5vTvbHlli8Whwpcu9NxWSRiA
=YLUw
-----END PGP SIGNATURE-----