Bridge+ebtables+VLAN+transparent proxy
"Andrew Cant" <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
As you can see from the subject I have recently been attempting to bridge a VLAN trunk (which works) and transparently redirect the HTTP traffic for caching and authentication (which does not work). The redirect is being done in iptables with the REDIRECT target. I am using the br-nf patch, and the packets appear to be getting to the IP layer from the bridge correctly. The redirect does work when bridging without the VLAN. It appears that the conntrack is not keeping track of the connection after it is redirected. The packet which is returned to the client seems to disappear in the iptables:Mangle:OUTPUT table. I assume that this is because of the missing conntrack entry? I have not familiarized myself with the inner workings of the conntrack/iptables, so I cannot say for sure. So I plan to throw in the towel, because it looks like some kernel work would be required to get this working and unfortunately I cannot justify the time to do it now. But before I give, I hope to double check that I am not being stupid and have missed something obvious :). Has anyone ever tried this kind of setup, or seen anything similar? Thanks in advanced for any comments/suggestions. Andrew ----------------------------------- Andrew Cant Developer LogiSense Corporation "IP Billing and Traffic Management" e: [email protected] p: 1-519-249-0508 x4108 w: www.logisense.com weblog: http://blog.logisense.com forum: https://ssl.logisense.com/support/forum ------------------------------------------------------- This SF.Net email is sponsored by: Power Architecture Resource Center: Free content, downloads, discussions, and more. http://solutions.newsforge.com/ibmarch.tmpl