All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] Linux bridging and cascaded switches
@ 2007-06-19 22:54 Greg Scott
  2007-06-19 23:03 ` Alex Samad
                   ` (7 more replies)
  0 siblings, 8 replies; 9+ messages in thread
From: Greg Scott @ 2007-06-19 22:54 UTC (permalink / raw)
  To: lartc

Hi -
 
Still plugging away at my Linux bridge/firewall and thinking through the
consequences.  In a normal firewall situation, the Internet is on one
side, the internal LAN on the other. Duh!  But now, with a Linux bridge
in the middle, the whole thing becomes one big messy LAN.  So we have a
scenario that looks like this:

Internal---User---Core-----Firewall---Internet---Internet router
Servers   switch  switch  (Bridged)    switch   (and default GW for
                                                 internal servers)

The scenario is a little more complex than I drew above because the
internal side has more than one LAN segment participating in the bridge.
I'm working on a way to simulate all this here - before going into
production - but I have a big question;

That firewall/bridge is no longer a router - it's a bridge.  Well, a
bridge that also does a bunch of stateful IP layer 3 filtering.  So now,
it will participate in a spanning tree setup with all those switches, on
both sides of it - right?  I'm guessing I want to turn off STP in this
case.  Am I on the right track?

Thanks

- Greg Scott
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2007-06-21  1:45 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-19 22:54 [LARTC] Linux bridging and cascaded switches Greg Scott
2007-06-19 23:03 ` Alex Samad
2007-06-19 23:35 ` Greg Scott
2007-06-20  3:31 ` Greg Scott
2007-06-20  4:07 ` Alex Samad
2007-06-20 20:58 ` John Default
2007-06-21  1:34 ` Grant Taylor
2007-06-21  1:41 ` Grant Taylor
2007-06-21  1:45 ` Grant Taylor

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.