Bridging and IPF

From: Mason Harding (mharding@marketnews.com)
Date: 03/28/01


From: "Mason Harding" <mharding@marketnews.com>
To: <security@FreeBSD.ORG>
Date: Wed, 28 Mar 2001 12:54:36 -0500

Hi. Has anyone had much luck with Bridging and IPF? As soon as I enable
bridging both IPF and IPFW stop filtering at all. If I set them both to
deny everything, they still let all packets pass. When I set
net.link.ether.bridge_ipfw=1 my system sits there for a second and then the
kernel crashes and reboots the machine. I can get
net.link.ether.bridge_ipfw set to 1 without a crash if I have no IP address
on any of the bridged interfaces, but I need an IP address so I can use my
external syslog server and ssh into the firewall(untill I know its running
well). Please help? Oh yah, its FreeBSD 4.2.

Thank you,
Mason

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Bridging and IPF
    ... Has anyone had much luck with Bridging and IPF? ... > bridging both IPF and IPFW stop filtering at all. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Bridging and IPF
    ... Has anyone had much luck with Bridging and IPF? ... >> kernel crashes and reboots the machine. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: pf OR ipf ?
    ... with the fact that there are now three filters (ipfw, ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: pf and bridging
    ... >> I wonder if it is possible to use the new pf firewall together with ... >> bridging as it is possible to use it with ipf and ipfw. ... I'll do the Layer 2 ipfw pfil_hook conversion next when I've finished ...
    (freebsd-net)
  • RE: inet socket restriction via group (fwd)
    ... Yes, but he said ipf, not ipfw.. ... understandings of what he's saying. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)