From: Grant Taylor <gtaylor@riverviewtech.net>
To: Mail List - Netfilter <netfilter@vger.kernel.org>
Subject: Re: Bridges
Date: Wed, 18 Aug 2010 16:51:04 -0500 [thread overview]
Message-ID: <4C6C55C8.5000905@riverviewtech.net> (raw)
In-Reply-To: <4C6B10CA.4090604@abpni.co.uk>
On 08/17/10 17:44, Jonathan Tripathy wrote:
> When using a single Linux host with lots of bridges, would there ever be
> a time, even for a few seconds, where traffic would "jump" bridges?
No. Such should not be possible.
> I know a previous poster mentioned that when adding a host to a bridge,
> for a few seconds all packets get sent everywhere, however does this
> only apply to the bridge that the new host was added to, or all bridges
> in the system?
I believe what the previous poster was alluding to was how a switch /
bridge goes in to dumb hub mode and forwards frames to unknown
destinations out all ports until it learns where the destination is.
This is standard operating procedure for switches / bridges, and is to
be expected.
I am not aware of any thing specific to bridges that would allow this to
happen (short of an as of yet unknown bug in the kernel). The closest
thing that I can think of that might make it seem like this is happening
is if someone is sending you some sort of VLAN hopping attack. And as I
(mis)understand that, that traffic would have to be with in a layer 2
network, so they attacker is likely to be close, not across the internet.
> Reason I ask is that I am considering have one bridge for public traffic
> and one bridge for private, and don't want private traffic to be seen by
> hosts connected to the public bridge.
I think you should be safe (enough) with this. In fact, you are
starting to get in to some more theoretical discussions about what is
and is not safe to do as far as having both public and private VLAN (or
bridge) traffic on the same wire (system). There are a number of people
(my self included) that think you are safe enough for most
non-uber-secure situations to go ahead and do what you are wanting to do.
Grant. . . .
next prev parent reply other threads:[~2010-08-18 21:51 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-08-17 22:44 Bridges Jonathan Tripathy
2010-08-17 22:56 ` Bridges Jan Engelhardt
2010-08-17 23:34 ` Bridges Stephen Hemminger
2010-08-18 11:27 ` Bridges Thomas Jacob
2010-08-18 19:51 ` Bridges Jonathan Tripathy
2010-08-18 21:51 ` Grant Taylor [this message]
2010-08-18 21:57 ` Bridges Jonathan Tripathy
2010-08-18 22:08 ` Bridges Grant Taylor
2010-08-18 22:15 ` Bridges Jonathan Tripathy
2010-08-18 22:26 ` Bridges Jan Engelhardt
2010-08-18 22:51 ` Bridges Jonathan Tripathy
2010-08-18 23:05 ` Bridges Pascal Hambourg
2010-08-18 23:07 ` Bridges Jonathan Tripathy
2010-08-18 23:21 ` Bridges Pascal Hambourg
2010-08-18 23:23 ` Bridges Jonathan Tripathy
2010-08-18 23:45 ` Bridges Jonathan Tripathy
2010-08-19 7:26 ` Bridges Pascal Hambourg
2010-08-19 18:47 ` Bridges Jonathan Tripathy
2010-08-19 19:26 ` Bridges Pascal Hambourg
2010-08-19 19:37 ` Bridges Jonathan Tripathy
2010-08-19 20:00 ` Bridges Jan Engelhardt
2010-08-19 20:11 ` Bridges Jonathan Tripathy
2010-08-19 21:14 ` Bridges Pascal Hambourg
2010-08-19 21:24 ` Bridges Jonathan Tripathy
2010-08-19 22:04 ` Bridges Pascal Hambourg
2010-08-19 22:53 ` Bridges Jonathan Tripathy
2010-08-20 8:53 ` Bridges Pascal Hambourg
2010-08-21 21:46 ` Bridges Jonathan Tripathy
2010-08-21 23:25 ` Bridges Jan Engelhardt
[not found] ` <4C70E853.6050107@abpni.co .uk>
2010-08-22 9:05 ` Bridges Jonathan Tripathy
2010-08-22 9:09 ` Bridges Jan Engelhardt
[not found] ` <4C70E 9A2.3040907@abpni.co.uk>
2010-08-22 9:10 ` Bridges Jonathan Tripathy
2010-08-22 21:02 ` Bridges Pascal Hambourg
[not found] ` <4C7194 D3.7070803@abpni.co.uk>
2010-08-22 21:21 ` Bridges Jonathan Tripathy
2010-08-23 8:22 ` Bridges Pascal Hambourg
2010-08-23 20:18 ` Bridges Jonathan Tripathy
2010-08-24 8:57 ` Bridges Karel Rericha
2010-08-24 14:44 ` Bridges Pascal Hambourg
2010-08-24 17:37 ` Bridges Jonathan Tripathy
2010-08-24 18:07 ` Bridges Pascal Hambourg
2010-08-24 18:34 ` Bridges Jonathan Tripathy
2010-08-24 22:20 ` Bridges Pascal Hambourg
2010-08-20 8:38 ` Bridges Jan Engelhardt
2010-08-20 9:05 ` Bridges Pascal Hambourg
2010-08-20 9:09 ` Bridges Jan Engelhardt
2010-08-20 10:26 ` Bridges Pascal Hambourg
2010-08-20 16:02 ` Bridges Grant Taylor
2010-08-20 16:18 ` Bridges Jan Engelhardt
2010-08-20 16:25 ` Bridges Grant Taylor
2010-08-20 16:32 ` Bridges Jan Engelhardt
2010-08-21 12:48 ` Bridges Pascal Hambourg
2010-08-21 21:44 ` Bridges Grant Taylor
2010-08-19 19:28 ` Bridges Jan Engelhardt
2010-08-18 22:59 ` Bridges Pascal Hambourg
2010-08-18 23:00 ` Bridges Jonathan Tripathy
2010-08-18 23:11 ` Bridges Pascal Hambourg
2010-08-19 8:29 ` Bridges Jan Engelhardt
2010-08-19 9:16 ` Bridges Pascal Hambourg
2010-08-19 3:52 ` Bridges Grant Taylor
2010-08-19 7:33 ` Bridges Pascal Hambourg
2010-08-19 14:51 ` Bridges Grant Taylor
2010-08-19 14:56 ` Bridges Jan Engelhardt
2010-08-19 15:49 ` Bridges Grant Taylor
2010-08-19 16:21 ` Bridges Jan Engelhardt
2010-08-19 16:41 ` Bridges Grant Taylor
2010-08-19 17:10 ` Bridges Jan Engelhardt
2010-08-19 18:36 ` Bridges Grant Taylor
2010-08-19 17:10 ` Bridges Rick Jones
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4C6C55C8.5000905@riverviewtech.net \
--to=gtaylor@riverviewtech.net \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox