Re: interface or source ip match using brouting - transparent proxy
Andrius Kazimieras Kasparavičius <[email protected]> Tue, 25 Apr 2006 21:41:40 +0300
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
* Bart De Schuymer <[email protected]> [2006-04-25 21:34]: > > I start from empty tables. I trid loging trafic and it logs correctly, > > but works incorrectly. I mean: I use the same broute rule: > > > > Bridge chain: BROUTING, entries: 1, policy: ACCEPT > > -p IPv4 -i eth0 --ip-src 10.0.0.0/8 --ip-proto tcp --ip-dport 80 > > --log-level debug --log-prefix "EBFW" --log-ip --log-arp -j redirect > > > > eth0 now is internal card, and it logs and works ash should be, but > > when I change the rule from eth0 to eth1, it does not log anymore, but > > it still redirects traffic locally, but it shouldn't?!? > > Log the packets as it enters the bridge and then see what kind of > alterations have been done to them. My guess is that the packets already > have the bridge's MAC address as destination. no, they do not. ok, what I noticed more is that, when ebtables logs, and all works as expected in ebtables, accepts redirects(intercepts) web port traffic, but iptables has no entries. Web traffic does not pass through the bridge. But if they are on wrong interface - the trafic will transparently flow through the bridge, but if iptables redirect rule in prerouting would appear - it would catch web trafic and redirect ignoring ebtables interface redirection settings. Temporary I can get away with that by using -m phys_dev with iptables, but it is workaroung afaik? Andrius ------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642