Hi Herman, We're using netfilter as a filtering bridge + NAT + local router between us and the the local university router (via which we are attached to *its* LAN) using proxy arp and iptables. It's been running happily for about 1.5 years (touch wood) supporting about 1200 hosts behind it. Cheers, Terry. [Charset iso-8859-1 unsupported, filtering to ASCII...] >Hi everybody, > >This question is not about iptables, but it is closely related, so somebody >might know the answer: >I am trying to construct a bridge, to filter 802.1q tags and protect a legacy >version 2.2 kernel server, while preserving port to port security on the LAN, >using the VLAN module. > >Can anybody refer me to some documentation on filtering on a bridge for the >2.4 kernel? > >Regards, >-- >Herman > >