[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

Freebsd 7 Network Bridge - Doesn't seem to be bridging

Asked by cforger in FreeBSD, Unix Operating Systems, Miscellaneous Networking, Linux Administration, Linux Distributions

Tags: FreeBSD, Bridge, if_bridge, Firewall, Routing

Hello,
 
 I'm trying to setup a very simple bridge on my FreeBSD 7.2 machine.

 The eventual goal is to use pf to filter the bridge, so I have a transparent firewall.

 My first stage was to setup a simple bridge, let everything pass, and then start locking it down via pf, but I can't get the box to pass packets properly via the bridge.

 I'm not even worrying about the pf side of things at the moment, I just want to move packets between both members of the bridge.

 This is the network;

em0 - WAN side - I have 255 IP's, lets call them 1.2.3.0-1.2.3.255
em1 - LAN side
msk0 - LAN side, management IP

1.2.3.1 is the DSL router on the WAN side

My rc.conf has this;

cloned_interfaces="bridge0"
ifconfig_bridge0="addm em0 addm em1 up"
ifconfig_em0="up"
ifconfig_em1="up"
 
The bridge0 interface is created properly, and the interfaces are up.

At this point, attempting to ping any WAN addresses doesn't work - due to no route to host, which isn't entirely surprising, as I don't have any routing info.

I think the way around this is to assign an IP to the bridge0 interface? When I assign a WAN address to the bridge0 interface (say 1.2.3.3), I can ping any other LAN addresses on my LAN (say 1.2.3.2 which is a different machine), but I can't ping any WAN addresses on the network like the 1.2.3.1 router.
Pings to 1.2.3.1 just hang, no "no route to host" type messages. arp -a lists the proper mac address for 1.2.3.1 but it takes a long time to resolve.  It does say that 1.2.3.1 is on bridge0, along with 1.2.3.3 (the ip I assigned to bridge), and 1.2.3.2 (the other physical machine)

This means I'm dead in the water for getting out on the internet.

The box is clean, not been frigged with.  I had some simple NAT with pf running earlier, so I know it can route internet traffic, but that's all off right now.

I think I'm just not understanding something here, maybe trying to do the impossible. Anyone see the error in my method? What should I do next in terms of troubleshooting? Thanks.
[+][-]10/06/09 02:29 AM, ID: 25503132Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/06/09 06:30 AM, ID: 25504747Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/06/09 06:31 AM, ID: 25504761Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/07/09 01:03 AM, ID: 25512991Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/07/09 04:20 AM, ID: 25514108Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/07/09 04:23 AM, ID: 25514127Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/08/09 02:31 AM, ID: 25523417Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/10/09 03:24 AM, ID: 25541697Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/10/09 11:51 AM, ID: 25543334Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/10/09 01:43 PM, ID: 25543735Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/10/09 02:42 PM, ID: 25543944Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/14/09 10:55 AM, ID: 25573176Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/15/09 01:17 AM, ID: 25578360Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/22/09 12:02 PM, ID: 25637755Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/22/09 01:01 PM, ID: 25638347Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81 - Hierarchy / EE_QW_3_20080625