Re: interface bonding

From: Richard Bejtlich (richard_bejtlich_at_yahoo.com)
Date: 01/09/04

  • Next message: Jez Hancock: "Re: Problem with DNS (UDP) queries"
    Date: Fri, 9 Jan 2004 13:52:55 -0800 (PST)
    To: freebsd-security@freebsd.org
    
    

    Ruslan wisely encouraged me to post the end result of
    my interface bonding quest. Here's how I bring up
    interfaces sf2 and sf3 against a new ngeth0 interface.
     I sniff the ngeth0 interface to see both TX outputs
    from my NetOptics tap:

    kldload ng_ether
    ifconfig sf2 promisc -arp up
    ifconfig sf3 promisc -arp up

    ngctl -f - << EOF
    mkpeer eiface dummy ether
    name .:dummy bond0
    EOF

    ngctl mkpeer bond0: one2many ether one
    ngctl connect sf2: bond0:ether lower many0
    ngctl connect sf3: bond0:ether lower many1

    ifconfig ngeth0 -arp up

    Thanks to everyone who provided input.

    Sincerely,

    Richard Bejtlich
    http://www.taosecurity.com

    __________________________________
    Do you Yahoo!?
    Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes
    http://hotjobs.sweepstakes.yahoo.com/signingbonus
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Jez Hancock: "Re: Problem with DNS (UDP) queries"

    Relevant Pages

    • Re: interface bonding
      ... sf2 and sf3 are real interfaces connected to my 10/100 ... ngctl mkpeer ngeth0: one2many lower one ...
      (FreeBSD-Security)
    • Re: netgraph arp issues vs linux veth
      ... still had to add the upper hooks up of the ngeth0 device to the bridge for it ... When I set this up with more than one virtual interface it appeared ... > Hook the lower and upper hooks of the physical interface up to the bridge. ... >>a sniff on the spoof machine listed this while pinging the remote machine ...
      (freebsd-net)
    • Creating span port using netgraph
      ... Basically, the span interface should receive a copy of all IP packets seen on my real network interfaces, with the purpose that snort can snoop this interface. ... ngctl mkpeer ngeth0: one2many lower one ...
      (freebsd-net)