Subject: Re: any 'brconfig' on NetBSD?
To: None <netbsd-help@netbsd.org>
From: James K. Lowden <jklowden@schemamania.org>
List: netbsd-help
Date: 10/06/2001 17:14:24
On Wed, Oct 03, 2001 at 02:56:48PM +0200, Matteo Salsilli wrote:
> Hi, I need to setup a bridge on my LAN, in order to connect a 2-NIC 
> BSD-box to both a cisco router and the internal LAN. Something like:
> 
> internet-----(ADSL)CISCO-----NIC(ae0)--BSD--NIC(sn0)-----LAN
> 
> I need bridge stuff because the CISCO has just the static IP, that my 
> provider set in it, and it offers no NAT or other services.

Matteo, 

Can I ask a dumb question, please?

You say you need a bridge because "the CISCO has just the static IP",
and I'm afraid I don't understand that (not that it's your job to
explain, of course).  

Isn't this the classic application of a firewall/gateway/router? 
Why wouldn't you use NAT and ipf at the ip level?  It seems to me a
bridge compromises security and gains nothing.  

Or am I missing something?

Regards, 

--jkl