LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-31-2009, 03:17 PM   #1
CoffeeKing!!!
Member
 
Registered: Mar 2008
Posts: 117

Rep: Reputation: Disabled
Anyone using a bridge firewall with iptables and ebtables?


Whether you are or are not, what are the pros and cons?
If you are, where and how much traffic is it seeing?
What are the specs of your equipment?
 
Old 11-01-2009, 09:46 AM   #2
janoszen
Member
 
Registered: Oct 2009
Location: Budapest
Distribution: Mostly Gentoo, sometimes Debian/(K)Ubuntu
Posts: 143

Rep: Reputation: 22
Pro, con

Wow, that is one cool project, I can tell you. Sun Microsystems has some appliance, which is basically a layer 2 firewall bridge. So you could set up a bridge between two ports without configuring an IP address on them, making the firewall almost invulnurable to attack. However, ebtables may be a problem performance-wise. Try and please please please do report back.

One little comment: if you are not using ebtables in the manner described above, there is almost no point in using it.
 
Old 11-02-2009, 10:02 AM   #3
CoffeeKing!!!
Member
 
Registered: Mar 2008
Posts: 117

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by janoszen View Post
Wow, that is one cool project, I can tell you. Sun Microsystems has some appliance, which is basically a layer 2 firewall bridge. So you could set up a bridge between two ports without configuring an IP address on them, making the firewall almost invulnurable to attack. However, ebtables may be a problem performance-wise. Try and please please please do report back.

One little comment: if you are not using ebtables in the manner described above, there is almost no point in using it.

I didn't know that Sun had that piece of equipment. I'm just going to use an old PC and two nics. I'm confused about why I should use Ebtables. I'm getting the feeling that Iptables has obsoleted it. Could you tell me how Ebtables hasn't been surpassed by Iptables?
 
Old 11-02-2009, 11:10 AM   #4
janoszen
Member
 
Registered: Oct 2009
Location: Budapest
Distribution: Mostly Gentoo, sometimes Debian/(K)Ubuntu
Posts: 143

Rep: Reputation: 22
Ebtables

To my knowledge iptables is layer 3 whereas ebtables is layer 2. In laymans terms you can't use iptables in a non-routed environment. If you were to set up the firewall on an ethernet bridge as I have suggested, you'd have to use ebtables. Well, in theory, I unfortunately never had the time to try it out.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ethernet bridging & iptables. Is ebtables needed also? utahnix Linux - Networking 4 04-21-2008 10:38 AM
IPTables interface switch (-i ethx) problem w/ bridge-Firewall lsbrasil Linux - Networking 3 02-09-2008 06:10 AM
Bridge/htb problem (ebtables) Mycado Linux - Networking 6 06-21-2006 04:58 AM
ebtables firewall vishamr2000 Linux - Security 1 04-09-2005 01:34 PM
802.1d Bridge + ebtables otisthegbs Linux - Wireless Networking 0 10-05-2004 07:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration