Filtering and Bridging

Patrick Dreker patrick@dreker.de
Sat, 29 Jul 2000 14:48:18 +0200


Hello...

I need to set up a packet filtering system here at our network, but due to
nature of the existing configuration I am having a pretty hard time...

The Problem is that our exterior gateway has an IP on the same subnet
as our network, and the only point where I can put the firewall into
the network is _between_ the gateway and our network:

Internet --- Gateway --- Firewall --- internal network
                  (all on the same subnet)

So I think the only real solution is to use a filtering bridge, which
leads me to the question: is netfilter compatible with the kernel
bridging facility? Can I configure a machine as a bridge (possibly
a transparent bridge) _AND_ use packet filtering on the same machine?

I have browsed the net for answers to my questions, but all documents on
bridging a pretty outdated, with regard to the kernel and netfilter.

Thanks in advance...

-- 
Patrick Dreker (patrick@dreker.de)
---------------------------------------------------------------
Some day the people who know how to use computers will rule
over those who don't.  -- Dilbert