2002-02-19 17:05:49

by Max

[permalink] [raw]
Subject: Ethernet bridging and firewalling

Will the patch
http://bridge.sourceforge.net/devel/bridge-nf/bridge-nf-0.0.6-against-2.4.17.diff

be included in mainstream?
It enables firewalling with bridging.

Best regards.


2002-02-23 22:35:23

by Harald Welte

[permalink] [raw]
Subject: Re: Ethernet bridging and firewalling

On Tue, Feb 19, 2002 at 08:09:25PM +0000, ertzog wrote:
> Will the patch
> http://bridge.sourceforge.net/devel/bridge-nf/bridge-nf-0.0.6-against-2.4.17.diff
>
> be included in mainstream?
> It enables firewalling with bridging.

No. The issues of this have been discussed on the netfilter developer meeting
(where Lennert was also present) - there's a summary available at
http://www.netfilter.org/documentation/events/netfilter-ws-2001-summary.txt

The basic issue is that it adds multiple new struct sk_buff members, which
is generally not considered as a good idea by the networking gods ;)

> Best regards.

--
Live long and prosper
- Harald Welte / [email protected] http://www.gnumonks.org/
============================================================================
GCS/E/IT d- s-: a-- C+++ UL++++$ P+++ L++++$ E--- W- N++ o? K- w--- O- M+
V-- PS++ PE-- Y++ PGP++ t+ 5-- !X !R tv-- b+++ !DI !D G+ e* h--- r++ y+(*)