Re: ipfilter won't filter bridged traffic on freebsd

This is a discussion on Re: ipfilter won't filter bridged traffic on freebsd within the IPFilter forums, part of the System Security and Security Related category; Hello Koen, On 09.02.2008, at 21:27, Koen Martens wrote: > http://coombs.anu.edu.au/~avalon/ipfilfaq....


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-09-2008
Manuel Kasper
 
Posts: n/a
Default Re: ipfilter won't filter bridged traffic on freebsd

Hello Koen,

On 09.02.2008, at 21:27, Koen Martens wrote:

> http://coombs.anu.edu.au/~avalon/ipfilfaq.html#freebsd1 suggests it
> is possible to use ipfilter to filter bridged traffic.
>
> However, this does not seem to be the case (unless 'recent' means
> more recent than 6.2-RELEASE-p10.


It sounds like you're using the old-style "BRIDGE" and not
if_bridge... If that's indeed the case, the reason why your bridged
traffic isn't passed through ipfilter is that ipfw is also loaded
(sounds dumb I know, but that's the way it's coded ;). Have a look at /
sys/net/bridge.c and search for "XXX: Prevent ipfw from being run
twice", and you'll know why this happens.

You can find a fix in the m0n0wall repository:

http://svn.m0n0.ch/wall/branches/fre...kernel-6.patch
(only the sys/net/bridge.c patch needs to be applied)

Or you could switch to if_bridge, which seems to be preferred now...
but according to its manpage, it has the same issue of running ipfw
twice (once directly, and once via pfil).

HTH,

Manuel
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:17 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0