Re: groking FORWARD chain

Bart De Schuymer <[email protected]> Tue, 16 Oct 2007 20:00:46 +0200
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Op di, 16-10-2007 te 06:03 -0400, schreef Bill McGonigle:
> Hi folks,
> 
> I'm hoping somebody can set me straight on the use of the FORWARD  
> chain.  At least, that's where I think my problem is (please prove me  
> wrong!).
> 
> Scenario:
> 
> I want to do some basic MAC-based filtering between a potentially  
> hostile machine A and machine B on a network.  Machine A is to be  
> allowed to speak to Machine B only (and ideally I'll only let Machine  
> B see Machine A's ARP broadcasts as well with some mangling later).  
> For now, I just want to implement MAC-based --src and --dst rules.
> 
> So, the goal is to put an ebtables box between Machine A and the rest  
> of the network.  For the sake of economy (possible replication for  
> other machines), reliability (solid-state), and power consumption,  
> I've got a Linksys WRT54GL with DD-WRT v24rc3 on it, including the  
> ebtables and ebtable_filter modules (kernel 2.4.35).  I started out  
> with OpenWRT Kamikaze but they claim ebtables is unstable on their  
> kernel.

They probably made some alterations to the vlan code which makes it
incompatible with ebtables...

cheers,
Bart



-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/