> A pure bridge doesn't need ARP. I don't get your point, > but my suggestion might not make much sense, I haven't > really thought about this. My little bridge-router systems could use ARP. I am putting together a site right now that uses an active/passive HA pair of firewall bridge/router systems. I kludge in a MAC Address for the active system to make the router in front of it happy, as well as sending out a GARP. This site needs bridging because it has H.323 videoconferencing equipment in place. H.323 devices - especially older ones - do not get along well with NAT. So I give the H.323 stuff a public IP Address and set up a bridge. This all worked nicely until the night before Easter when I tried a new version and everything broke. But I can live with not knowing the out interface from L3 as long as I know the in-interface. - Greg -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html