Re: iptables / bridge mode
In article <3E2B294E.email@example.com> firstname.lastname@example.org writes:
>I needed to setup a firewall after the network was taken i production,
>so i decided to go bridge mode in order to make the integration
>completely transparent(except for the 30 seconds for the box to learn
>the routing tables and 5 secs to move the plug)
Another way of doing it is a single-address proxy-arp firewall. Like
the bridge solution, there is no need to reconfigure anything but the
firewall. Unlike the bridge, it will show up on traceroutes.
I've got a production single-address proxy-arp firewall with about 200
systems behind it (incoming connection is a t3) on 5 segments.
At some point, I should write it up as a mini-howto. Using the ip
command to control the details of interface configuration and routing
is the main unusual thing.
Blars Blarson email@example.com
"Text is a way we cheat time." -- Patrick Nielsen Hayden