Ethernet Bridge on RedHat not passing traffic
Ive setup a bridge with eth1, and eth2, using br0 interface. when I run tcpdump on the bridge interface I see packets from both interfaces, but they are not passing. I get the same results with iptables on and off, I believe my iptables are correct, bellow is some out put as far as my config.
[root@ips ~]# tcpdump -i br0
tcpdump: WARNING: br0: no IPv4 address assigned
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on br0, link-type EN10MB (Ethernet), capture size 65535 bytes
21:06:16.775169 ARP, Request who-has adsvr01.h1tb.com tell vc.h1tb.com, length 46
21:06:16.775537 ARP, Request who-has vc.h1tb.com tell adsvr01.h1tb.com, length 46
21:06:24.877900 IP adsvr01.h1tb.com.bootps > 255.255.255.255.bootpc: BOOTP/DHCP, Reply, length 300
21:06:33.865442 IP adsvr01.h1tb.com.bootps > 255.255.255.255.bootpc: BOOTP/DHCP, Reply, length 300
21:06:36.143829 ARP, Request who-has adsvr01.h1tb.com tell win2k3_x32.h1tb.com, length 46
21:06:40.130752 ARP, Request who-has adsvr01.h1tb.com tell win2k3_x32.h1tb.com, length 46
21:06:42.084565 ARP, Request who-has adsvr01.h1tb.com tell win2k3_x32.h1tb.com, length 46
21:06:44.083409 ARP, Request who-has adsvr01.h1tb.com tell win2k3_x32.h1tb.com, length 46
21:06:44.167751 ARP, Request who-has 172.31.253.1 tell win2k3_x32.h1tb.com, length 46
21:06:48.130647 IP win2k3_x32.h1tb.com.netbios-ns > 172.31.253.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
21:06:48.880776 IP win2k3_x32.h1tb.com.netbios-ns > 172.31.253.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
21:06:49.396226 ARP, Request who-has 172.31.253.1 tell win2k3_x32.h1tb.com, length 46
21:06:49.630694 IP win2k3_x32.h1tb.com.netbios-ns > 172.31.253.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
21:06:50.084116 ARP, Request who-has adsvr01.h1tb.com tell win2k3_x32.h1tb.com, length 46
21:06:50.873408 IP adsvr01.h1tb.com.bootps > 255.255.255.255.bootpc: BOOTP/DHCP, Reply, length 300
[root@ips ~]# brctl show
bridge name bridge id STP enabled interfaces
br0 8000.005056a9000b yes eth1
eth2
DEVICE="br0"
TYPE=Bridge
STP=on
ONBOOT=yes
BOOTPROTO=none
NM_CONTROLLED=no
DEVICE="eth1"
ONBOOT=yes
BRIDGE=br0
TYPE=Ethernet
BOOTPROTO=none
DEVICE="eth2"
ONBOOT=yes
BRIDGE=br0
TYPE=Ethernet
BOOTPROTO=none
[root@ips ~]# sysctl -a | grep bridge
net.bridge.bridge-nf-call-arptables = 0
net.bridge.bridge-nf-call-iptables = 0
net.bridge.bridge-nf-call-ip6tables = 0
net.bridge.bridge-nf-filter-vlan-tagged = 0
net.bridge.bridge-nf-filter-pppoe-tagged = 0
[root@ips ~]# iptables -vL
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
2172 164K ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
1 60 ACCEPT icmp -- any any anywhere anywhere
0 0 ACCEPT all -- lo any anywhere anywhere
0 0 ACCEPT tcp -- any any anywhere anywhere state NEW tcp dpt:ssh
35 6765 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- br0 any anywhere anywhere
0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
|