Re: firewalling PPPOE stream without terminating it

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Harald Welte wrote:

For those just joining, I'm trying to put a box between my DSL modem and my ethernet switch to enable me to filter up to 5 PPPoE streams. Harald suggested I move the discussion to the proper lists.

I would like to ask you this question at an apropriate mailinglist
(netfilter@xxxxxxxxxxxxxxxxxxx, or the lartc mailinglist [since the
assumption that you would need to do NAT in case you terminate the two
dsl lines is invalid an can be solved using policy routing + connmark]).

Okay, so you're suggesting terminating all the connections on the new box and then using policy routing to forward the packets on to the appropriate address(es) on the internal side? And since the PPPoE headers have been removed, I could then use standard iptables to do the filtering?


Chris





--
Chris Friesen                    | MailStop: 043/33/F10
Nortel Networks                  | work: (613) 765-0557
3500 Carling Avenue              | fax:  (613) 765-2986
Nepean, ON K2H 8E9 Canada        | email: cfriesen@xxxxxxxxxxxxxxxxxx



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux