Re: please help me with ebtables, i need to block arp replys
Grant Taylor <[email protected]> Tue, 19 Aug 2008 21:13:26 -0500
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
On 8/19/2008 8:23 PM, mikis stepan wrote: > Hi, thanks for your fast reply. What i really want to do is the > second scenario, i just have the linksys wrtsl54gs which is a > router/switch and to that router are connected 3 computers, computer > A, computer B and computer C, computer A is the machine that > responses the arp request that are made in the lan, and i want that > only those replys be allowed by the linksys. For example, if computer > B makes an arp request to computer C, computer C will send his reply, > but i want a rule that drop that reply in the router, at the same > time computer A will answer that request, but his reply will be > allowed by the router, and that reply will go to computer B. The > program that makes the arp replys, in each arp reply packet, in the > ethernet header, in the source mac address field, puts the mac > address of computer A, every arp replys has computers A mac address > in ethernet header in mac source adddress field, and thats the > criterio that i want to use to decide if the arp reply is allowed. I > want to know if i can do this with ebtables, i want to know which > table and chain could help me with this. I know that the mac address > of computer A could be used by another machine in the lan, and those > replys could be accepted too, but thats another problem that i will > resolve later. I just need a rule in the linksys that will check the > arp replys and if the arp replys comes from computer A, then accept, > if not, then drop. Thats what i need and i want to know if this is > possible with ebtables?? Sorry for my english. Thanks a lot for your > help in advance. Ming-Ching is probably correct. This falls back to that to the best of my knowledge most SOHO routers are built as multiple components, one of which is a small 4 (really 5) port switch and a single ethernet port. I say really 5 because the fifth port is connected to the CPU as the second network interface. I may be wrong, but I doubt it. If you do an ifconfig on the router you should see two ethernet interfaces, not five. If you do see five, you can create the bridge and have the CPU do what you want to do. Also, if the small switch can be layer 2 managed and create a VLAN per port, you can do the same thing with VLAN tagging. Grant. . . . ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/