LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-30-2006, 12:50 PM   #1
vishamr2000
Member
 
Registered: Aug 2004
Posts: 210

Rep: Reputation: 31
ARP and IPTables!!


Hi to all,

I wanted to know if there is a way of relaying (forwarding) ARP requests and replies using iptables. What rule can I use?

Regards,
Visham
 
Old 01-31-2006, 06:22 AM   #2
ichrispa
Member
 
Registered: Mar 2005
Location: Dresden, Germany
Distribution: OpenSuse 11.2/3, Debian 5.0 , Debian 1.3.1, OpenBSD
Posts: 277

Rep: Reputation: 32
Rule is foreward or nat. NAT requres the iptables ip module to be loaded.

Redirection over NAT appears to b protocol independent (at least as far as subprotocols of IP are concerned). Search the manpages if iptables support the opition "--protocol arp"
 
Old 01-31-2006, 11:28 PM   #3
vishamr2000
Member
 
Registered: Aug 2004
Posts: 210

Original Poster
Rep: Reputation: 31
Hi to all,

I did check the manpages for iptables but didn't find it.Do you know of any ways in which I can filter arp packets using iptables? I don't want to use ebtables to do that because I will have to convert the firewall into a bridge as well.

Any help will be very much appreciated..

Warm regards,
Visham
 
Old 02-01-2006, 01:38 AM   #4
dudulz
Member
 
Registered: Feb 2005
Location: Australia
Distribution: [Redhat] [Slackware] [SuSe] [FreeBSD]
Posts: 81

Rep: Reputation: 15
I suggess you must compile your kernel again with support ARP Filtering in Network Option.
 
Old 02-02-2006, 12:24 AM   #5
vishamr2000
Member
 
Registered: Aug 2004
Posts: 210

Original Poster
Rep: Reputation: 31
Hi,

I did compile the kernel with the Arptables support but it supports only INPUT and OUTPUT chains. I need to forward arp replies which have had their destination mac address modified. The forwarding will make the arp packets go to their real destination based on target ip address.

How can I do that? I know that we can use the br_nf option to forward arp packets but the PC has to be set up as a bridgefirewall, which I don't want..

Is there any other way?

Many thx for the replies..

Warm regards,
Visham
 
Old 02-04-2006, 12:20 AM   #6
vishamr2000
Member
 
Registered: Aug 2004
Posts: 210

Original Poster
Rep: Reputation: 31
Hi to all,

I compiled a 2.6.13 kernel (using RH9) with all the options regarding ARP filtering in Network options. But I still can't use commands like arptables -A IN -j DROP. It gives me an error. When I try man arptables, it tells me it's not found.

Do I have to do something more (install some userspace program or sth) to get it to work? Is the mere selection of the ARP kernel options not sufficient?

Any help will be very much appreciated..

Warm regards,
Visham
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange ARP behavior : A linux server responds to all ARP requests Hdvd21 Linux - Networking 4 10-24-2013 05:02 AM
iptables v1.2.9: Unknown arg `/sbin/iptables' Try `iptables -h' or 'iptables --help' Niceman2005 Linux - Security 4 12-29-2005 08:20 PM
Disabling ARP probes after receiving an ARP request AltecLansingMan Linux - Networking 1 03-30-2004 01:25 PM
proxy arp or forwarding via iPtables for DMZ? piratebiter Linux - Networking 0 08-28-2003 11:34 AM
How to create an proxyarp entry in arp table by using arp command? himalayas Linux - Networking 0 06-04-2003 04:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration