Re: BRIDGE HELP
AA Inter.Network Services / SYED JAHANZAiB <[email protected]> Sat, 12 Jan 2008 12:32:45 +0000
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
--===============0613168442== Content-Type: multipart/alternative; boundary="_2977109e-b53d-4c80-8341-0a6d1052a7fd_" --_2977109e-b53d-4c80-8341-0a6d1052a7fd_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable So far, I have achieved the goal of Mac filtering on Bridge with the help o= f this ebtables mailing List. However by taking ideas , I implement the top= ology using IPTABLES. (speciall thanks to Mr. Grant) I wouldnt be able to d= o this by my own. Now I want to setup DHCP Server for about 200 users. I want that DHCP shoul= d pickup entries from a file /etc/allowed.macip and assign fix ip to allowe= d users. How can I setup DHCP server to pick entries from a file so that sp= ecific macs gets fix ips every time. Thx in advace Regards,=20 SYED JAHANZAIB =20 > Date: Fri, 11 Jan 2008 13:11:08 -0600 > From: [email protected] > To: [email protected] > Subject: Re: [Ebtables-user] BRIDGE HELP >=20 > On 01/11/08 04:48, Peter Volkov wrote: > > But remember that it's always possible to spoof mac address. So if=20 > > you do not have enough smart switches with port security which allow=20 > > you physically bind one port - one client, you should=20 > > authenticate/authorize your users by other means: VPN, pppoe, etc... >=20 > Something else you may want to look in to, if your switches support it,=20 > is 802.1x authentication. This way, only your clients will be able to=20 > get on to your network. >=20 > Yes, VPNs, PPPoE, and the likes will add extra authenticity / control /=20 > security to your network. However they add extra over head and=20 > processing requirements too. There is also the fact that some of them=20 > do not play well with things that require a large MTU. >=20 > Now if your clients had a Linux box at each location, you could do some=20 > interesting things that would provide the authenticity / control /=20 > security that you want with out having all the overhead. >=20 >=20 >=20 > Grant. . . . >=20 > ------------------------------------------------------------------------- > Check out the new SourceForge.net Marketplace. > It's the best place to buy or sell services for > just about anything Open Source. > http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketpl= ace > _______________________________________________ > Ebtables-user mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/ebtables-user _________________________________________________________________ Share life as it happens with the new Windows Live. http://www.windowslive.com/share.html?ocid=3DTXT_TAGHM_Wave2_sharelife_0120= 08= --_2977109e-b53d-4c80-8341-0a6d1052a7fd_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <style> .hmmessage P { margin:0px; padding:0px } body.hmmessage { FONT-SIZE: 10pt; FONT-FAMILY:Tahoma } </style> </head> <body class=3D'hmmessage'> So far, I have achieved the goal of Mac filtering on Bridge with the help o= f this ebtables mailing List. However by taking ideas , I implement the top= ology using IPTABLES. (speciall thanks to Mr. Grant) I wouldnt be able to d= o this by my own.<br><br>Now I want to setup DHCP Server for about 200 user= s. I want that DHCP should pickup entries from a file /etc/allowed.macip an= d assign fix ip to allowed users. How can I setup DHCP server to pick entri= es from a file so that specific macs gets fix ips every time.<br><br><div>&= nbsp;Thx in advace<br><BR> <font color=3D"#0066ff"><strong><font color=3D"#000000">Regards,</font> </s= trong></font><BR> <div><font color=3D"#0066ff"></font></div> <div><strong><font color=3D"#0033ff">SYED JAHANZAIB</font></strong></div> <div><strong><font color=3D"#0033ff"></font></strong> <br></div></div><br>&= gt; Date: Fri, 11 Jan 2008 13:11:08 -0600<br>> From: gtaylor@riverviewte= ch.net<br>> To: [email protected]<br>> Subject: Re:= [Ebtables-user] BRIDGE HELP<br>> <br>> On 01/11/08 04:48, Peter Volk= ov wrote:<br>> > But remember that it's always possible to spoof mac = address. So if <br>> > you do not have enough smart switches with por= t security which allow <br>> > you physically bind one port - one cli= ent, you should <br>> > authenticate/authorize your users by other me= ans: VPN, pppoe, etc...<br>> <br>> Something else you may want to loo= k in to, if your switches support it, <br>> is 802.1x authentication. T= his way, only your clients will be able to <br>> get on to your network.= <br>> <br>> Yes, VPNs, PPPoE, and the likes will add extra authentici= ty / control / <br>> security to your network. However they add extra o= ver head and <br>> processing requirements too. There is also the fact = that some of them <br>> do not play well with things that require a larg= e MTU.<br>> <br>> Now if your clients had a Linux box at each locatio= n, you could do some <br>> interesting things that would provide the aut= henticity / control / <br>> security that you want with out having all t= he overhead.<br>> <br>> <br>> <br>> Grant. . . .<br>> <br>&g= t; ------------------------------------------------------------------------= -<br>> Check out the new SourceForge.net Marketplace.<br>> It's the b= est place to buy or sell services for<br>> just about anything Open Sour= ce.<br>> http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.ne= t/marketplace<br>> _______________________________________________<br>&g= t; Ebtables-user mailing list<br>> [email protected]<b= r>> https://lists.sourceforge.net/lists/listinfo/ebtables-user<br><br />= <hr />Share life as it happens with the new Windows Live. <a href=3D'http:/= /www.windowslive.com/share.html?ocid=3DTXT_TAGHM_Wave2_sharelife_012008' ta= rget=3D'_new'>Start sharing!</a></body> </html>= --_2977109e-b53d-4c80-8341-0a6d1052a7fd_-- --===============0613168442== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------- Check out the new SourceForge.net Marketplace. It's the best place to buy or sell services for just about anything Open Source. http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketplace --===============0613168442== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ebtables-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/ebtables-user --===============0613168442==--