Re: please help me with ebtables, i need to block arp replys
Grant Taylor <[email protected]> Tue, 19 Aug 2008 21:30:28 -0500
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
On 8/19/2008 9:13 PM, Taylor, Grant wrote: > Ming-Ching is probably correct. This falls back to that to the best of > my knowledge most SOHO routers are built as multiple components, one of > which is a small 4 (really 5) port switch and a single ethernet port. I > say really 5 because the fifth port is connected to the CPU as the > second network interface. I may be wrong, but I doubt it. If you do an > ifconfig on the router you should see two ethernet interfaces, not five. > If you do see five, you can create the bridge and have the CPU do what > you want to do. Also, if the small switch can be layer 2 managed and > create a VLAN per port, you can do the same thing with VLAN tagging. Another nasty hack that you might be able to do is to send out Gratuitous ARPs so that systems will already know where a given system is so that they don't need to ARP for it. This /might/ work for you most of the time. Though I'm not sure what the real system will do when it sees another system GARPing for it. Grant. . . . ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/