We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

Iptables and Transparent Bridge dont working

ipsystems
ipsystems asked
on
Medium Priority
565 Views
Last Modified: 2008-03-17
Hi,
We configure a slack with a transparent bridge, but IPTABLES dont block traffic passing throught the bridge.

Are there any known problem to use iptables in a transparente bridge?  Any solution for this problem?

Please, it's urgent.


Regards,
Luiz
Comment
Watch Question

Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:

The Ebtables syntax is similar or equal iptables?

Commented:
Yes. Very similar.

But you have to install it and recompile a kernel with it. It's standard in 2.6, but you need to patch your 2.4 kernel.

Then, install the user space tools.

Their site is pretty informative and very helpful in setting this up.

There is unfortunately no easier way.

Author

Commented:

yes...I'll try to install it! :(

I already install cbq, snort with acid and Snortsam blocking with iptables!... but when I try to block from bridge....the bad news!...

Well...let's go! :)

Author

Commented:

Can you help a little more?

I install ebtables and it works fine... but I have difficult to make some rules, because is a little different from IPtables.

For exemple, I don't know how to block ICMP attemp and dun know how to block a port 25 for exemple.... the website does not have a complete exemples.

Take a look:
http://ebtables.sourceforge.net/examples.html#real

Thanks for any help


Luiz

Commented:
ebtables -A FORWARD --ip-proto 1 -j DROP # 1 is ICMP
ebtables -A INPUT --ip-proto 1 -j DROP

ebtables -A FORWARD --ip-proto IPv4 --ip-destination-port 25 -j DROP
ebtables -A INPUT --ip-proto IPv4 --ip-destination-port 25 -j DROP

I don't have an ebtables installed box in here, so it's hard to test, but these should work.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.