Re: Linux firewall for public IP's

This is a discussion on Re: Linux firewall for public IP's within the Linux Networking forums, part of the Linux Forums category; Martin Cooper <usenet@martinc.me.uk> wrote in message news:<gemini.3ef4132f003af543%usenet@martinc.me.uk >... &...


Go Back   Usenet Forums > Linux Forums > Linux Networking

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-24-2003
Richard Luong
 
Posts: n/a
Default Re: Linux firewall for public IP's

Martin Cooper <usenet@martinc.me.uk> wrote in message news:<gemini.3ef4132f003af543%usenet@martinc.me.uk >...
> Hi Richard,
> The way I solve this problem is by using a bridging firewall, but to
> set this up, you need to patch the linux kernel. For details of how to
> do this, take a look at http://bridge.sourceforge.net, particularly have
> a look through the docs.
>
> Normally when you create a bridge, it works at layer 2, so netfilter
> never sees the traffic going through the bridge. However, after
> patching and rebuilding the kernel with the bridging patch, this part of
> the process is changed so that all traffic traverses the netfilter
> tables. So you end up with a machine where the two (or more) ethernet
> cards are joined to form a single bridge, then assign an IP to that
> bridge (optional). This immediatly saves you one IP, and all machines
> can be on the same subnet but still firewalled.
>
> On my network, I use a bridge with 3 ethernet cards. eth0 connects
> directly to my router, eth1 connects to my DMZ and eth2 connects to a
> switch to server the local network. An additional benefit of a bridge
> is that it does not appear in the traceroute output, so is invisible to
> any would be attacker.



Martin,

It worked. Thanks for the bridge information.

Richard.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:37 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0