Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Grant Taylor <gtaylor@riverviewtech.net>
To: Mail List - Netfilter <netfilter@vger.kernel.org>
Subject: Re: Bridges
Date: Wed, 18 Aug 2010 16:51:04 -0500	[thread overview]
Message-ID: <4C6C55C8.5000905@riverviewtech.net> (raw)
In-Reply-To: <4C6B10CA.4090604@abpni.co.uk>

On 08/17/10 17:44, Jonathan Tripathy wrote:
> When using a single Linux host with lots of bridges, would there ever be 
> a time, even for a few seconds, where traffic would "jump" bridges?

No.  Such should not be possible.

> I know a previous poster mentioned that when adding a host to a bridge, 
> for a few seconds all packets get sent everywhere, however does this 
> only apply to the bridge that the new host was added to, or all bridges 
> in the system?

I believe what the previous poster was alluding to was how a switch / 
bridge goes in to dumb hub mode and forwards frames to unknown 
destinations out all ports until it learns where the destination is. 
This is standard operating procedure for switches / bridges, and is to 
be expected.

I am not aware of any thing specific to bridges that would allow this to 
happen (short of an as of yet unknown bug in the kernel).  The closest 
thing that I can think of that might make it seem like this is happening 
is if someone is sending you some sort of VLAN hopping attack.  And as I 
(mis)understand that, that traffic would have to be with in a layer 2 
network, so they attacker is likely to be close, not across the internet.

> Reason I ask is that I am considering have one bridge for public traffic 
> and one bridge for private, and don't want private traffic to be seen by 
> hosts connected to the public bridge.

I think you should be safe (enough) with this.  In fact, you are 
starting to get in to some more theoretical discussions about what is 
and is not safe to do as far as having both public and private VLAN (or 
bridge) traffic on the same wire (system).  There are a number of people 
(my self included) that think you are safe enough for most 
non-uber-secure situations to go ahead and do what you are wanting to do.



Grant. . . .

  parent reply	other threads:[~2010-08-18 21:51 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-08-17 22:44 Bridges Jonathan Tripathy
2010-08-17 22:56 ` Bridges Jan Engelhardt
2010-08-17 23:34   ` Bridges Stephen Hemminger
2010-08-18 11:27 ` Bridges Thomas Jacob
2010-08-18 19:51   ` Bridges Jonathan Tripathy
2010-08-18 21:51 ` Grant Taylor [this message]
2010-08-18 21:57   ` Bridges Jonathan Tripathy
2010-08-18 22:08     ` Bridges Grant Taylor
2010-08-18 22:15       ` Bridges Jonathan Tripathy
2010-08-18 22:26         ` Bridges Jan Engelhardt
2010-08-18 22:51           ` Bridges Jonathan Tripathy
2010-08-18 23:05             ` Bridges Pascal Hambourg
2010-08-18 23:07               ` Bridges Jonathan Tripathy
2010-08-18 23:21                 ` Bridges Pascal Hambourg
2010-08-18 23:23                   ` Bridges Jonathan Tripathy
2010-08-18 23:45                   ` Bridges Jonathan Tripathy
2010-08-19  7:26                     ` Bridges Pascal Hambourg
2010-08-19 18:47                       ` Bridges Jonathan Tripathy
2010-08-19 19:26                         ` Bridges Pascal Hambourg
2010-08-19 19:37                           ` Bridges Jonathan Tripathy
2010-08-19 20:00                             ` Bridges Jan Engelhardt
2010-08-19 20:11                               ` Bridges Jonathan Tripathy
2010-08-19 21:14                             ` Bridges Pascal Hambourg
2010-08-19 21:24                               ` Bridges Jonathan Tripathy
2010-08-19 22:04                                 ` Bridges Pascal Hambourg
2010-08-19 22:53                                   ` Bridges Jonathan Tripathy
2010-08-20  8:53                                     ` Bridges Pascal Hambourg
2010-08-21 21:46                                       ` Bridges Jonathan Tripathy
2010-08-21 23:25                                         ` Bridges Jan Engelhardt
     [not found]                                           ` <4C70E853.6050107@abpni.co   .uk>
2010-08-22  9:05                                           ` Bridges Jonathan Tripathy
2010-08-22  9:09                                             ` Bridges Jan Engelhardt
     [not found]                                               ` <4C70E 9A2.3040907@abpni.co.uk>
2010-08-22  9:10                                               ` Bridges Jonathan Tripathy
2010-08-22 21:02                                                 ` Bridges Pascal Hambourg
     [not found]                                                   ` <4C7194 D3.7070803@abpni.co.uk>
2010-08-22 21:21                                                   ` Bridges Jonathan Tripathy
2010-08-23  8:22                                                     ` Bridges Pascal Hambourg
2010-08-23 20:18                                                       ` Bridges Jonathan Tripathy
2010-08-24  8:57                                                         ` Bridges Karel Rericha
2010-08-24 14:44                                                         ` Bridges Pascal Hambourg
2010-08-24 17:37                                                           ` Bridges Jonathan Tripathy
2010-08-24 18:07                                                             ` Bridges Pascal Hambourg
2010-08-24 18:34                                                               ` Bridges Jonathan Tripathy
2010-08-24 22:20                                                                 ` Bridges Pascal Hambourg
2010-08-20  8:38                                   ` Bridges Jan Engelhardt
2010-08-20  9:05                                     ` Bridges Pascal Hambourg
2010-08-20  9:09                                       ` Bridges Jan Engelhardt
2010-08-20 10:26                                         ` Bridges Pascal Hambourg
2010-08-20 16:02                                           ` Bridges Grant Taylor
2010-08-20 16:18                                             ` Bridges Jan Engelhardt
2010-08-20 16:25                                               ` Bridges Grant Taylor
2010-08-20 16:32                                                 ` Bridges Jan Engelhardt
2010-08-21 12:48                                             ` Bridges Pascal Hambourg
2010-08-21 21:44                                               ` Bridges Grant Taylor
2010-08-19 19:28                         ` Bridges Jan Engelhardt
2010-08-18 22:59   ` Bridges Pascal Hambourg
2010-08-18 23:00     ` Bridges Jonathan Tripathy
2010-08-18 23:11       ` Bridges Pascal Hambourg
2010-08-19  8:29       ` Bridges Jan Engelhardt
2010-08-19  9:16         ` Bridges Pascal Hambourg
2010-08-19  3:52     ` Bridges Grant Taylor
2010-08-19  7:33       ` Bridges Pascal Hambourg
2010-08-19 14:51         ` Bridges Grant Taylor
2010-08-19 14:56           ` Bridges Jan Engelhardt
2010-08-19 15:49             ` Bridges Grant Taylor
2010-08-19 16:21               ` Bridges Jan Engelhardt
2010-08-19 16:41                 ` Bridges Grant Taylor
2010-08-19 17:10                   ` Bridges Jan Engelhardt
2010-08-19 18:36                     ` Bridges Grant Taylor
2010-08-19 17:10                   ` Bridges Rick Jones

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4C6C55C8.5000905@riverviewtech.net \
    --to=gtaylor@riverviewtech.net \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox