Subject: Re: NetBSD as a bridge/firewall
To: None <>
From: Matthias Scheler <>
List: current-users
Date: 08/11/2002 08:26:26
In article <>,
	Kevin Sullivan <> writes:
> I'm setting up a firewall for a small business's DSL line.  They have a /28
> coming out of the DSL modem.  Since there is no place to put a router (and
> they don't want NAT), I'd like to set up a bridge/firewall where a computer
> acts as a ethernet bridge and also filters packets.  Can this be done with
> NetBSD 1.6?

NetBSD can't do filtering on a bridge. The only way to handle this
scenario is using proxy arp. Assuming you get from your
provider and the NetBSD machines has two interface "fxp0" and "epic0"
your setup could look like this:

fxp0: netmask	connected to DSL modem
epic0: netmask	connected to LAN

Now use "arpd" from "pkgsrc/net/arpd" to provide proxy arp for
to on "fxp0".

	Kind regards

Matthias Scheler