Avatar of ipsystems
ipsystems asked on

Iptables and Transparent Bridge dont working

Hi,
We configure a slack with a transparent bridge, but IPTABLES dont block traffic passing throught the bridge.

Are there any known problem to use iptables in a transparente bridge?  Any solution for this problem?

Please, it's urgent.


Regards,
Luiz
Linux Networking

Avatar of undefined
Last Comment
Alf666

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Alf666

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
ipsystems


The Ebtables syntax is similar or equal iptables?
Alf666

Yes. Very similar.

But you have to install it and recompile a kernel with it. It's standard in 2.6, but you need to patch your 2.4 kernel.

Then, install the user space tools.

Their site is pretty informative and very helpful in setting this up.

There is unfortunately no easier way.
ASKER
ipsystems


yes...I'll try to install it! :(

I already install cbq, snort with acid and Snortsam blocking with iptables!... but when I try to block from bridge....the bad news!...

Well...let's go! :)

Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
ASKER
ipsystems


Can you help a little more?

I install ebtables and it works fine... but I have difficult to make some rules, because is a little different from IPtables.

For exemple, I don't know how to block ICMP attemp and dun know how to block a port 25 for exemple.... the website does not have a complete exemples.

Take a look:
http://ebtables.sourceforge.net/examples.html#real

Thanks for any help


Luiz
Alf666

ebtables -A FORWARD --ip-proto 1 -j DROP # 1 is ICMP
ebtables -A INPUT --ip-proto 1 -j DROP

ebtables -A FORWARD --ip-proto IPv4 --ip-destination-port 25 -j DROP
ebtables -A INPUT --ip-proto IPv4 --ip-destination-port 25 -j DROP

I don't have an ebtables installed box in here, so it's hard to test, but these should work.