Subject: Re: bridged interfaces? (for ipfilter)
To: Michael Graff <>
From: Stefan Grefen <>
List: tech-net
Date: 09/08/1998 10:13:28
In message <>  Michael Graff wrote:
> (Danny Thomas) writes:
> > I asked Darren about whether it could be run in a bridge configuration and
> > he didn't think so. Is there an easy way to do this or has BSD networking
> > been focussed more on routing interfaces?

Hmm man 5 ipf says there is the "to" keyword which allows you to switch
packets directly to an interface bypassing the routing code.
(this -current )

This should do the trick for IP-based protocols. 

> Most Unix networking has been on routing, not bridging.  I think I know
> what would be needed to do real bridging, but I don't think you would
> gain anything with the IP filtering code in there, without making it
> far more generic and putting the accept or deny hook at a much, much
> lower level.
> I _could_ imagine a BPF-based bridge, which might be what that drawbridge
> thing really is; I've not looked at it.

That could be used to transfer the non-IP protocols you can't filter with
ipf anyway.

> --Michael


Stefan Grefen                                Tandem Computers Europe Inc.                       High Performance Research Center
 --- Hacking's just another word for nothing left to kludge. ---