On 10/10/2007, Cidric THIBAULT wrote:
Huh? If you understand NAT very well, then how is that unfortunate?
I'm not trying to be a prick here; I honestly have trouble
understanding you.
> I's right it's not seems to be interesting to nat some machine in the same
Is this what you are trying to say?:
"It's true that it would not seem to make sense to do Network Address
Translation between machines that are on the same physical network
segment, but this is what I want."
I'll give you an example of what I understood. Please tell me if this
describes what you are trying to do:
- You have multiple hosts on a single physical network segment.
- An OpenBSD box is also connected to the same network segment,
possibly intercalated between two parts of that network, where one
part of that network is connected to its 1st NIC and the other to a
2nd NIC.
- There are hosts on both sides that are on the same logical subnet.
Therefore bridging is required.
- There are other hosts connected to that same physical network
segement that are configured with IP addresses and subnet masks so
that they are in a second different logical subnet. They need NAT in
order to talk to the hosts in the first logical subnet.
Is this what you need?
> The problem, you said it very well, it's the firewall can't assign it's own
You can assign an IP address to a NIC that's part of a bridge. This is
frequently done, so the bridge can be remotely administered with SSH.
In this scenario you put both NICs in promiscuous mode (so they listen
to all traffic and bridge whatever is allowed in pf.conf), but you
assign an IP address to one of the NICs anyway. Most users will never
see/know that IP. It doesn't appear in their network settings. It's
strictly for when you want to talk directly to the OpenBSD box.
> So, the idea is to set a particular IP on all trafic outgoing from the
I have no idea what you're trying to say here.
> The rule could be this one :
I have no idea what you're trying to do here. I'm missing contextual
information.
| Srivatsa Vaddagiri | containers (was Re: -mm merge plans for 2.6.23) |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Benjamin Herrenschmidt | Re: [PATCH] Remove process freezer from suspend to RAM pathway |
git: | |
| Jarek Poplawski | [PATCH take 2] pkt_sched: Protect gen estimators under est_lock. |
| David Miller | [GIT]: Networking |
| Gerhard Pircher | 3c59x: shared interrupt problem |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
