Re: Re: [Ebtables-user] bridge/ebtables interaction...

Bart De Schuymer <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
Op di, 24-05-2005 te 16:05 -0700, schreef Stephen Hemminger:
> On Tue, 24 May 2005 18:26:00 -0400
> Jon Anderson <janderson-PLjm5N+tXOMV+D8aMU/[email protected]> wrote:
> 
> > Stephen Hemminger wrote:
> > 
> > >That implies a bad bridge topology (not tree), so that can't be legal.
> > >There can be only one (active) path to another node or the possiblities
> > >of loops exist and bridging won't work!
> > >  
> > >
> > Bad bridge topology...or a hostile user. A user with physical access and
> > the ability to change his/her mac address can bring down a network
> > simply by snagging a MAC and sending packets through the bridge.
> > 
> 
> Then how do you propose to stop them? One way that makes sense is to drop the
> offending packets and defer the update of the forwarding database until after the prerouting hook.
> That assumes that no routing hook rewrites the source address, but that shouldn't be that
> hard. Is that what you already proposed?

That's what my first reaction was. The disadvantage of this is that any
packet that is dropped in PREROUTING doesn't update the fdb. I'm not
sure if that's so bad, probably not. One could argue that the update to
the fdb is part of the forwarding decision. If you don't have a problem
with it I'd also prefer to just postpone the update. It's a lot simpler
than adding a new chain.

cheers,
Bart




-------------------------------------------------------
This SF.Net email is sponsored by Yahoo.
Introducing Yahoo! Search Developer Network - Create apps using Yahoo!
Search APIs Find out how you can build Yahoo! directly into your own
Applications - visit http://developer.yahoo.net/?fr=offad-ysdn-ostg-q22005
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.