Re: Filtering arp on vlan trunk interface

[email protected] Sat, 01 Sep 2007 20:27:35 +0200
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Grant Taylor wrote:
> I need to ask.  Do you have the "Bridged IP/ARP packets filtering" 
> (CONFIG_BRIDGE_NETFILTER) turned on in your kernel?  I ask because this 
> determines if IPTables will see bridged packets or not.  If this option 
> is turned on then you will need to be aware that IPTables will see and 
> effect bridged traffic.  If this option is not turned on then IPTables 
> will have no bearing on bridged traffic.  I would almost be willing to 
> bet that it is on and should probably be turned off in your situation.

Yes, CONFIG_BRIDGE_NETFILTER is enabled in the kernel. The description of this option says "...will 
let arptables resp. iptables see bridged ARP resp. IP traffic."
Wouldn't this mean that disabling this option will lead to bridged ip traffic not being fed into 
iptables? This would be a major disadvantage in my setup, because this host indeed is a bridging 
firewall and needs to filter all of the traffic that's flowing through it.

How would disabling this option affect the arp table of the bridge?


Best,

Lars

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/