Re: source-mac filtering

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On January 11, 2004 02:05 pm, Tarek W. wrote:
> On Sun, 2004-01-11 at 18:37, Ramin Dousti wrote:
> > dhcpd takes and puts packets by netlink sockets which bypass the whole
> > IP stack. So in short, you cannot filter the requests nor the response.
> >
> > Ramin

	I'll accept that .. but I have a question ... is ARP routing not 
	related?? 
	Are ARP queries not ethernet broadcasts on a similar level to 
	DHCP broadcasts??

	(okay .. thats mighty off topic ..but perhaps its something we can 
	consider network related)

	Alistair

>
> <snippage>
>
> this is slightly off... iirc, some of the negotiation happens that way,
> further negotiation does not... what I'm sure of however is that if u
> don't explicitely allow dhcpd traffic server-side, negotiation does not
> work client-side... which means that not all traffic if any bypasses
> netfilter... don't have the time to investigate further server-side...
> sorry...


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux