Subject: Re: Transparent Firewall w/ NetBSD
To: David Wetzel <dave@turbocat.de>
From: Jon Lindgren <jlindgren@espus.com>
List: netbsd-help
Date: 07/18/2000 07:34:14
On Tue, 18 Jul 2000, David Wetzel wrote:

[snip]

> I dont know about 1.4.2 but I use this:
> 
> [CISCO] <-10BaseTCrossovercable-> [ NETBSD Tlp1 IPFilter Tlp0] <---> LAN
> 
> the cisco and the Tlp1 network card is on an different net. (2 usable IPs)
> 
> It just works.

[snip]

Yeah.  This is a routing configuration.  A bridging configuration will not
consume IP addresses... it's similar to an ethernet switch which will
filter packets.  Packet comes in, the box realizes that it must be bridged
to another segment, and figures "hey, why not throw it through IPFilter,
too."  Of course, you can't do NAT in such a situation, but it's a great
option for situations where you've got a bunch of static IPs from a
provider, and you don't want to do IP filter on n different boxes.

-Jon
 --------------------------------------------------------------------
 "Hey - this old machine screams like a snail on acid!" - (a true
  comment by a fellow who recently installed NetBSD on an old server)