Re: Bridges

From: Jeremie Le Hen (jeremie_at_le-hen.org)
Date: 09/29/05

  • Next message: Doug Barton: "Re: Minor issues in our rcNG"
    Date: Thu, 29 Sep 2005 11:08:18 +0200
    To: Yar Tikhiy <yar@comp.chem.msu.su>
    
    

    Hi Yar,

    > Couldn't you bridge across the parent, or trunk, physical interfaces
    > carrying tagged VLAN traffic then? (Of course, hardware support for
    > VLAN should be turned off on them in that case.)

    Since neither ipfw nor pf can filter on VLAN tag at layer 2, this
    could be pretty useful to be able to bridge vlan(4) interfaces together.
    For administrative reasons, you may not want to have all the VLANs
    living onto a physical network being seen to the other side of the
    bridge.

    I also know another situation where this can be useful. Once I've been
    asked to build a single firewall for a whole rack of servers. These
    servers where remotely administrated by customers and therefore we
    had no security control over them. Thus we wanted the firewall to
    protect the servers from the Internet but also from others round servers,
    that may have been defaced. For other reasons, we needed a bridge and
    no NAT was possible. The idea was to give each server its own VLAN,
    and the firewall bridged them together.

    I set up this firewall with Linux, I would be glad to be able to do
    so with FreeBSD.

    Regards,

    -- 
    Jeremie Le Hen
    < jeremie at le-hen dot org >< ttz at chchile dot org >
    _______________________________________________
    freebsd-arch@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-arch
    To unsubscribe, send any mail to "freebsd-arch-unsubscribe@freebsd.org"
    

  • Next message: Doug Barton: "Re: Minor issues in our rcNG"

    Relevant Pages

    • Re: Controlling access to MSTSC.exe
      ... to get through the windows firewall. ... static configuration by using VLANS in conjunction with a VLAN Policy Server ... > programs where I will need the ability to restrict by ... >>> level policy (i.e. who can connect via remote desktop to the servers). ...
      (microsoft.public.windowsxp.setup_deployment)
    • Re: routing problem help plz
      ... They should be in VLAN 1 if it has an ip ... After that check the trunking between your switches (if servers are ... If this works then let me know and after that we will deal with your EIGRP ... > Default networks accepted from incoming updates ...
      (comp.dcom.sys.cisco)
    • Re: Connecting to Multiple networks
      ... Well to be honest they are not really fussed about a firewall, ... PIX and stop the VLan Nonsence. ... >>> firewall then public facing servers and then firewall then private data ... Everyone else here are Cisco network engineers and have Unix ...
      (microsoft.public.win2000.networking)
    • Re: [fw-wiz] Worms, Air Gaps and Responsibility
      ... isolate desktop and laptop systems from servers using switches and the firewall ... Cisco offers "Private VLAN" capabilities in their layer 2 switches. ... VLAN you can designate ports as private or public. ... Using a firewall and defined interfaces that can be adequately ...
      (Firewall-Wizards)
    • Re: PIX firewalling web servers
      ... How would using a VLAN help me to firewall the ... >things behind the firewall are servers. ... switch will take care of the routing between the VLANs for you. ...
      (comp.security.firewalls)