Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Iptables and Transparent Bridge dont working

Posted on 2004-03-30
6
Medium Priority
?
530 Views
Last Modified: 2008-03-17
Hi,
We configure a slack with a transparent bridge, but IPTABLES dont block traffic passing throught the bridge.

Are there any known problem to use iptables in a transparente bridge?  Any solution for this problem?

Please, it's urgent.


Regards,
Luiz
0
Comment
Question by:ipsystems
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 9

Accepted Solution

by:
Alf666 earned 2000 total points
ID: 10719026
iptables can't "see" bridge packets.

See ebtables for this :

http://ebtables.sourceforge.net/
0
 

Author Comment

by:ipsystems
ID: 10719238

The Ebtables syntax is similar or equal iptables?
0
 
LVL 9

Expert Comment

by:Alf666
ID: 10719281
Yes. Very similar.

But you have to install it and recompile a kernel with it. It's standard in 2.6, but you need to patch your 2.4 kernel.

Then, install the user space tools.

Their site is pretty informative and very helpful in setting this up.

There is unfortunately no easier way.
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 

Author Comment

by:ipsystems
ID: 10719306

yes...I'll try to install it! :(

I already install cbq, snort with acid and Snortsam blocking with iptables!... but when I try to block from bridge....the bad news!...

Well...let's go! :)

0
 

Author Comment

by:ipsystems
ID: 10723107

Can you help a little more?

I install ebtables and it works fine... but I have difficult to make some rules, because is a little different from IPtables.

For exemple, I don't know how to block ICMP attemp and dun know how to block a port 25 for exemple.... the website does not have a complete exemples.

Take a look:
http://ebtables.sourceforge.net/examples.html#real

Thanks for any help


Luiz
0
 
LVL 9

Expert Comment

by:Alf666
ID: 10725804
ebtables -A FORWARD --ip-proto 1 -j DROP # 1 is ICMP
ebtables -A INPUT --ip-proto 1 -j DROP

ebtables -A FORWARD --ip-proto IPv4 --ip-destination-port 25 -j DROP
ebtables -A INPUT --ip-proto IPv4 --ip-destination-port 25 -j DROP

I don't have an ebtables installed box in here, so it's hard to test, but these should work.
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question