Re: [fw-wiz] Tranparent bridge

From: Paul Robertson (proberts_at_patriot.net)
Date: 09/25/03

  • Next message: Bill Royds: "Re: [fw-wiz] snpp"
    To: Tony Rall <trall@almaden.ibm.com>
    Date: Thu, 25 Sep 2003 13:07:01 -0400 (EDT)
    
    

    On Thu, 25 Sep 2003, Paul Robertson wrote:

    > A non-transparent bridge will modify the MAC address of the
    > packets as it bridges them between networks, a transparent bridge will
    > forward all the layer 2 traffic unaltered. The right combination of proxy
    > arp and forwarding might technically make a non-transparent bridge (if
    > you did all the broadcast/multicast stuff too.) The main advantage would
    > be in having smaller ARP tables at each node.

    Just to be complete, if you're not doing proxy ARP, the advantage would be
    in figuring out if a packet came through the bridge. If a segment had
    multiple bridges in, it would help figure out where a packet came from
    when troubleshooting.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Bill Royds: "Re: [fw-wiz] snpp"

    Relevant Pages

    • Re: www wherewasi? cd 28 06 06
      ... I like the idea of having a bridge named after me. ... First up is a small town, 6½ miles northeast, also on the ... aforementioned river. ...
      (uk.rec.competitions)
    • Re: www wherewasi? cd 28 06 06
      ... Thanks Paul, so late too, or should I say early, hope your PC ok. ... I like the idea of having a bridge named after me. ... First up is a small town, 6½ miles ... also on the aforementioned river. ...
      (uk.rec.competitions)
    • Re[2]: [PATCH] ethernet-bridge: update skb->priority in case forwarded frame has VLAN-header
      ... bridge should update skb->prioriry for properly QoS ... PM> skb->priority to an arbitary value or derive it from vlan priority or IP ... BG> If this packet came in from an 802.1Q VLAN device, ...
      (Linux-Kernel)
    • Debugging bridge behavior
      ... I have a bridge between two ports where a packet comes into one port ... packets physically connected to eth1 on the VM host system. ... tcpdump: WARNING: eth1: no IPv4 address assigned ...
      (comp.os.linux.networking)
    • Re: bridge callbacks in if_ed.c?
      ... > Gleb Smirnoff wrote: ... > That depends on how many systems are behind the bridge. ... >> driver, it must pass its frames to Ethernet stack ... > packet is arrving double in the upper half? ...
      (freebsd-net)