> It filters based on packet content that just happens to be IP
> information. Just like the u32 filter, except the syntax is easier.
> It still bridges.

i guess you are right. my only problem is that a bridge does MAC/SNAP
and is independent of transport level protocols. but a netfilter
bridge still bridges...

the cisco pix can act transparently too (i.e. below the IP layer), but
it's an IP firewall and not a bridge.

this discussion is "splitting hairs" - as we say in german, but noone
is being forced to participate. i do believe that linux bridging +
netfilter should be handled as a linux transparent firewall, but not
as a bridge. i will probably be in touch with the bridging team about

