12.07.2015 Views

download

download

download

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 1067:65:31:00:00:00 1 flags=6200:00:00:62:67:65 3159772 flags=159:80:00:01:00:00 2516844544 flags=1000:04:96:10:5b:90 fxp1 1173 flags=004:00:00:00:00:04 0 flags=1700:00:00:a6:04:00 ?? 0 flags=0As you can see in the ifconfig output, Bridge-member interfaces have differentflags, each having its own meaning, which is given in the following table:Flag Ifconfig switch DescriptionDISCOVER discover Interface forwards packets to all interfaces forunknown destinations.LEARNING learn Learns host addresses from incoming packet headers.STICKY sticky Does not expire address entries and keeps them in tact.SPAN span Puts interface into monitor mode. The interfacetransmits a copy of all bridge packets. Used for sniffingon bridge interfaces.STP stp Enables 802.1d Spanning Tree protocol to preventloops.EDGE edge Edge ports are connected directly to hosts and hence,cannot create loops. Interface starts forwarding packetsas soon as it is up.AUTOEDGE autoedge Automatically detects edge status.PTP ptp Point-to-point link that starts forwarding immediately.This is used for connection to other switches thatsupport RSTP protocol.AUTOPTP autoptp Automatically detects ptp mode.Filtering BridgesA bridge is used as a firewall in situations where you do not want to segment yournetwork. Since a typical firewall is also a router (a layer3 node), you actually need toplace it as your network gateway. In such case, you will have to justify your subnets.But when a firewall acts as a layer2 host (a bridge), there is no need to reconfigureyour network and the firewall can be deployed ad-hoc.To enable IPFW to filter traffic between bridged interfaces, you should enable theappropriate sysctl variable:# sysctl net.link.ether.bridge.ipfw=1[ 171 ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!