From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Gerry Weaver" Subject: iptables bridge filter question Date: Thu, 18 Mar 2004 02:28:28 -0600 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_000E_01C40C90.B2BBE9E0" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_000E_01C40C90.B2BBE9E0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Hello All, I have setup a bridging firewall. I want to drop packets on the external interface, which have source addresses on my internal network. However, the firewall/bridge sits between my T1 router and the rest of my LAN. Is there a way to drop the packets mentioned previously, but allow the router? I guess a rule could be created that uses the routers mac address as a match. I've been playing around with this, but I'm not getting the result I want. I could sure use some advice on this. [ LAN xx.xx.xx.0/24 ]<==>[ bridge/firewall ]<==>[ router xx.xx.xx.254/24 ] Thanks in advance, Gerry --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.576 / Virus Database: 365 - Release Date: 1/30/2004 ------=_NextPart_000_000E_01C40C90.B2BBE9E0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello=20 All,
 
I have = setup a=20 bridging firewall. I want to drop packets on the external interface, = which have=20 source addresses on my internal network. However, the firewall/bridge = sits=20 between my T1 router and the rest of my LAN. Is there a way to drop the = packets=20 mentioned previously, but allow the router? I guess a rule could be = created that=20 uses the routers mac address as a match. I've been playing around with = this, but=20 I'm not getting the result I want. I could sure use some advice on=20 this.
 
[ LAN = xx.xx.xx.0/24=20 ]<=3D=3D>[ bridge/firewall ]<=3D=3D>[ router xx.xx.xx.254/24 = ]
 
 
Thanks = in=20 advance,
Gerry
------=_NextPart_000_000E_01C40C90.B2BBE9E0--