From: Carla Schroder <carla@bratgrrl.com>
To: bridge@lists.osdl.org
Subject: [Bridge] combination WAP/firewall/router - wired and wireless hosts do not connect
Date: Wed, 17 Jan 2007 20:09:22 -0800 [thread overview]
Message-ID: <200701172009.22444.carla@bratgrrl.com> (raw)
hey all,
I searched the archives and the site and didn't find an answer, so if I missed
something I'll gladly take pointers to any good help pages.
I want to build a combination wireless access point/iptables firewall/router
for my home LAN, like this:
dsl modem - router/WAP - switch - LAN
I have Pyramid Linux on a PC Engines WRAP board. The board has an Atheros
tri-mode wireless card, and two wired Ethernet ports in use. The configs are
like this:
LAN IP = 192.168.1.25
br0 = ath0 bridged to eth0
WAN IP = 22.33.44.55
eth1
When my iptables firewall is up, all hosts have Internet and can ping the
router. But wired hosts cannot ping wireless hosts, or the reverse. With the
firewall turned off, the bridge works perfectly and all LAN hosts see each
other.
I've tried running my iptables rules one at a time, and the showstopper is the
forwarding chain. I like to use a default policy of FORWARD DROP, then write
accept rules as needed. But nothing I have tried works here, and it's not
like my iptables-fu is all that mighty anyway.
Should I be looking at ebtables, or can I do this in iptables? Or what?
thanks in advance.
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Carla Schroder
Linux geek and random computer tamer
check out my Linux Cookbook!
http://www.oreilly.com/catalog/linuxckbk/
best book for sysadmins and power users
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
next reply other threads:[~2007-01-18 4:09 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-01-18 4:09 Carla Schroder [this message]
2007-01-18 14:54 ` [Bridge] combination WAP/firewall/router - wired and wireless hostsdo not connect Richard Davis
2007-01-22 18:56 ` [Bridge] combination WAP/firewall/router - wired and wireless hosts do " Abel Martín
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200701172009.22444.carla@bratgrrl.com \
--to=carla@bratgrrl.com \
--cc=bridge@lists.osdl.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox