From: Misterke <netfilter@quintux.com>
To: netfilter@vger.kernel.org
Subject: Re: Problems with bridge+router setup
Date: Mon, 28 Dec 2015 21:59:56 +0100 [thread overview]
Message-ID: <b574dcf038177fbbc8f8ea2baeff61fd@vpn.quintux.com> (raw)
In-Reply-To: <5681839F.4080801@plouf.fr.eu.org>
On 2015-12-28 19:46, Pascal Hambourg wrote:
> I am not saying to use VLAN tagging. I am asking whether the
> communication between the cable modem and the TV box over the LAN
> uses
> VLAN tagging, because I have seen it with a triple-play provider, and
> in
> that case it is easy to identify which packets must be bridged :
> those
> with a VLAN tag.
Ah, sorry for the misunderstanding. Is there any way I could find out?
The supplier (Telenet) isn't communicating much on what it is doing
between
its Set-Top_Boxes and the cable-modem, but putting them behind a router
does break the interactive functions (and hence also video-on-demand).
>> Would passing all ARP requests and broadcast frames be dangerous
>> from a
>> security point-of-view?
>
> It depends what your security requirements are. Beyond security, it
> could disrupt normal operations of the hosts on the network.
Well, my security needs are pretty simple: nothing from the Internet
(so
the cable-modem) should be able to get to anything on a host of type A
(unless being forwarded through iptables of course). But I'm pretty
paranoia ...
When I now think about it, I guess this will never be 100% safe:
possibly
the cable-modem could be hacked and since the B client (digital STB) is
directly reachable from the cable-modem, that one could also be
compromised
and then just giving it an extra IP address within my LAN range, would
allow access to the LAN ... Perhaps I need to rethink the original
idea
completely ... I assume setting up a VLAN for the B clients could
address this, but then I would need something more complex than a
simple
switch near the clients, correct?
Thanks,
K
next prev parent reply other threads:[~2015-12-28 20:59 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-12-27 11:00 Problems with bridge+router setup Kurt Haenen
2015-12-27 19:21 ` Neal P. Murphy
2015-12-28 9:57 ` Misterke
2015-12-28 10:44 ` Pascal Hambourg
2015-12-28 16:33 ` Misterke
2015-12-28 18:46 ` Pascal Hambourg
2015-12-28 20:59 ` Misterke [this message]
2015-12-28 23:28 ` Pascal Hambourg
2015-12-28 22:50 ` Neal P. Murphy
2016-01-02 11:26 ` Misterke
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b574dcf038177fbbc8f8ea2baeff61fd@vpn.quintux.com \
--to=netfilter@quintux.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox