Re: groking FORWARD chain
Bart De Schuymer <[email protected]> Tue, 16 Oct 2007 20:00:46 +0200
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Op di, 16-10-2007 te 06:03 -0400, schreef Bill McGonigle: > Hi folks, > > I'm hoping somebody can set me straight on the use of the FORWARD > chain. At least, that's where I think my problem is (please prove me > wrong!). > > Scenario: > > I want to do some basic MAC-based filtering between a potentially > hostile machine A and machine B on a network. Machine A is to be > allowed to speak to Machine B only (and ideally I'll only let Machine > B see Machine A's ARP broadcasts as well with some mangling later). > For now, I just want to implement MAC-based --src and --dst rules. > > So, the goal is to put an ebtables box between Machine A and the rest > of the network. For the sake of economy (possible replication for > other machines), reliability (solid-state), and power consumption, > I've got a Linksys WRT54GL with DD-WRT v24rc3 on it, including the > ebtables and ebtable_filter modules (kernel 2.4.35). I started out > with OpenWRT Kamikaze but they claim ebtables is unstable on their > kernel. They probably made some alterations to the vlan code which makes it incompatible with ebtables... cheers, Bart ------------------------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/