[TriLUG] Linux as a bridge?

Mike Johnson mike at enoch.org
Wed Dec 26 17:43:37 EST 2001


gregbrown at mindspring.com [gregbrown at mindspring.com] wrote:
> Can a linux box with two ethernet interfaces act as a bridge at layer 2?  I
> know I can route between two interfaces but I'd like to use two interfaces as 
> a bridge where I can apply my firewall rules.  Any ideas? > 

I've never done it before, but it theoretically works.  Check out
http://bridge.sourceforge.net
http://www.math.leidenuniv.nl/pipermail/bridge/

You'll need the bridge-nf stuff.  

For MAC address filtering:
http://users.pandora.be/bart.de.schuymer/ebtables/

> Currently the only layer 2 firewall I'm aware of is the Lucent Brick, but I'd
> sure like to aviod spending the $1500.00 (plus SMS server) and use a linux 
> box.

OpenBSD with their firewall (pf) can do layer two firewalling, as can
ipfilter on any of the OSes on which it runs.

Mike
-- 
"Yeah it is! Cause he's bakin' in the...kitchen of darkness!  A pie of
lost souls...until it's golden brown!" -- Moltar on Space Ghost



More information about the TriLUG mailing list