Re: [SLUG] Bridging Firewall

From: Andrew M Hoerter (amh@pobox.com)
Date: Thu Jun 19 2003 - 10:28:00 EDT


There's no reason that shouldn't work. I for one would be curious to know
how it works out. The platform I'm most familiar with for
firewalling purposes, OpenBSD, can't do transparent bridging with NAT.
Among other problems, it won't respond to ARP queries for the NAT address
unless the second interface is configured with that address. The packets
get translated but no replies ever make it back. I don't know if they're
ever planning on fixing this issue, since it's well-rooted in how the BSD
IP stack and firewall software works.

But Linux's networking code is totally different, so perhaps you won't
have that problem.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 17:01:05 EDT