From owner-freebsd-ipfw@FreeBSD.ORG Wed Apr 9 14:24:35 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8DB0C37B41B for ; Wed, 9 Apr 2003 14:24:34 -0700 (PDT) Received: from sccrmhc01.attbi.com (sccrmhc01.attbi.com [204.127.202.61]) by mx1.FreeBSD.org (Postfix) with ESMTP id B958543F75 for ; Wed, 9 Apr 2003 14:24:33 -0700 (PDT) (envelope-from crist.clark@attbi.com) Received: from blossom.cjclark.org (12-234-159-107.client.attbi.com[12.234.159.107]) by sccrmhc01.attbi.com (sccrmhc01) with ESMTP id <2003040921243200100ognque>; Wed, 9 Apr 2003 21:24:32 +0000 Received: from blossom.cjclark.org (localhost. [127.0.0.1]) by blossom.cjclark.org (8.12.8p1/8.12.3) with ESMTP id h39LOVki000701; Wed, 9 Apr 2003 14:24:31 -0700 (PDT) (envelope-from crist.clark@attbi.com) Received: (from cjc@localhost) by blossom.cjclark.org (8.12.8p1/8.12.8/Submit) id h39LOS8B000700; Wed, 9 Apr 2003 14:24:28 -0700 (PDT) X-Authentication-Warning: blossom.cjclark.org: cjc set sender to crist.clark@attbi.com using -f Date: Wed, 9 Apr 2003 14:24:28 -0700 From: "Crist J. Clark" To: Shawn Barnhart Message-ID: <20030409212428.GA460@blossom.cjclark.org> References: <00b301c2fb7a$218b14a0$0201a8c0@twinstar> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <00b301c2fb7a$218b14a0$0201a8c0@twinstar> User-Agent: Mutt/1.4.1i X-URL: http://people.freebsd.org/~cjc/ cc: freebsd-ipfw@freebsd.org Subject: Re: fwd and bridging X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: "Crist J. Clark" List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Apr 2003 21:24:35 -0000 On Sat, Apr 05, 2003 at 07:49:03AM -0600, Shawn Barnhart wrote: > The manpage states that fwd rules (like for transparent proxying) will not > match bridged packets. Will they ever, or is there some fundamental reason > they can't? Bridged packets are never processed at the IP layer, that is, they never get passed to the ip_input() function. All of the 'fwd' code lives in ip_input() and ip_output() at the IP layer and above. -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org