Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 15 Apr 2006 11:53:52 +0200
From:      Fabian Keil <freebsd-listen@fabiankeil.de>
To:        "Daniel O'Connor" <doconnor@gsoft.com.au>
Cc:        freebsd-net@freebsd.org
Subject:   Re: How to use if_bridge
Message-ID:  <20060415115352.1ef82bb1@localhost>
In-Reply-To: <200604151053.25089.doconnor@gsoft.com.au>
References:  <200604142048.20189.doconnor@gsoft.com.au> <20060414140709.20c51ebc@localhost> <200604151053.25089.doconnor@gsoft.com.au>

next in thread | previous in thread | raw e-mail | index | archive | help
--Sig_fPotYHSh/4uP.t3yYX94tMJ
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

"Daniel O'Connor" <doconnor@gsoft.com.au> wrote:

> On Friday 14 April 2006 21:37, Fabian Keil wrote:

> > Depending on your firewall setup you might have to disable
> > some of the net.link.bridge sysctls as well.
>=20
> I don't have any firewalls in the kernel for simplicity at this stage.

If I'm not mistaken you have to disable net.link.bridge.pfil_onlyip
then. From the if_bridge man page:

|net.link.bridge.pfil_onlyip  Set to 1 to only allow IP packets to
|                             pass when packet filtering is enabled (subjec=
t to
|                             firewall rules), set to 0 to unconditionally
|                             pass all non-IP Ethernet frames.

It's enabled by default.

Fabian
--=20
http://www.fabiankeil.de/

--Sig_fPotYHSh/4uP.t3yYX94tMJ
Content-Type: application/pgp-signature; name=signature.asc
Content-Disposition: attachment; filename=signature.asc

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (FreeBSD)

iD4DBQFEQMKxjV8GA4rMKUQRAssCAKCS96aE3PgYKumaLOnWmEsmUXDgBgCWNVu8
aDYYYn9ssmWprsL4NW4yPw==
=CXLa
-----END PGP SIGNATURE-----

--Sig_fPotYHSh/4uP.t3yYX94tMJ--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060415115352.1ef82bb1>