This should be emphasized, as there seems to be a good deal of confusion about what's included in the kernel and what isn't. 1) Bridging is included in the kernel 2) Using iptables (or ebtables for that matter) to filter bridge traffic is not included and must be patched in. Check out http://bridge.sourceforge.net/docs.html or http://ebtables.sourceforge.net/documentation.html for more details. -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx]On Behalf Of Richard Doyle Sent: Tuesday, December 16, 2003 11:35 AM To: netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: Bridging firewall setup On Tue, 2003-12-16 at 08:55, Chris Brown wrote: > Hi all, new to the list. I'm trying to get a bridging firewall setup on > a RH 9 box and I'm not having much luck. The bridge itself works fine > but when I try to add rules using netfilter they seem to be ignored and > packets I'm trying to block go on through. I've been digging through the > list archives, google, various forums and HOWTOs and I still haven't > found the answer so I'm hoping someone here can point out what I'm doing > wrong :) Did you patch the kernel to support this? The bridging code in the stock 2.4 kernels doesn't support firewalling,