Author | Message |
---|---|
![]() |
|
MonarchX Replies: 1 Views: 500 |
![]() |
How can I bind local IP addresses and/or MAC addresses to specific interfaces (eth0, br0, wlan0, etc.) via IPTables and/or EBTables and/or ARPTables? Assume default policy has to be ACCEPT.
The wa ... |
|
![]() |
|
![]() |
|
MonarchX Replies: 14 Views: 2446 |
![]() |
I think somewhere here around, it was explained very much in details, what is the reason, why layer 2 filtering is not going to happen...
DDWRT SPI firewall works on WAN to LAN and LAN to WAN traffic ... |
|
![]() |
|
![]() |
|
MonarchX Replies: 14 Views: 2446 |
![]() |
Just to summarize what I wanted from initial thread was to find an answer on how isolate 2 LAN clients on the same subnet and same VLAN (or no VLAN) via EBTables, but it doesn't appear to be possible, ... | |
![]() |
|
![]() |
|
MonarchX Replies: 13 Views: 2794 |
![]() |
I don't want to make yet another EBTables thread, but I'd like to know how to view EBTables counters. Command from EBTables manpages doesn't work. In fact, several guides state that EBTables is bugged ... | |
![]() |
|
![]() |
|
MonarchX Replies: 14 Views: 2446 |
![]() |
LAN Port to LAN Port is handled by the switch. The router does not see these packets and cannot filter them. As far as I have seen, no switch in dd-wrt supports filtering.
So is it DD-WRT firmware ... |
|
![]() |
|
![]() |
|
MonarchX Replies: 14 Views: 2446 |
![]() |
MAC address filtering (layer 2) can be done with ebtables or iptables. It's like whack-a-mole, you're dancing around a topic trying to find a solution for something that may not have one that is clea ... | |
![]() |
|
![]() |
|
MonarchX Replies: 14 Views: 2446 |
![]() |
IPTables = Layer 3 filtering
ARPTables = ARP filtering EBTables = Layer 2 filtering (including ARP), but only for Bridge interfaces What NetFilter tools exist for Layer 2 filtering on Non-Bridge ... |
|
![]() |
|
![]() |
|
MonarchX Replies: 4 Views: 1011 |
![]() |
Wireshark labels those abnormal requests as "ARP Announce" and "Gratuitous". I assume my SysCTL.conf just ignores such requests. | |
![]() |
|
![]() |
|
MonarchX Replies: 4 Views: 1011 |
![]() |
I don't like to share more info than necessary about my topology, but what is going on seems to fit the definition of Gratuitous ARP Attack Cache Poisoning - https://github.com/mehiar/ARP-Poisoning-an ... | |
![]() |
|
![]() |
|
MonarchX Replies: 4 Views: 1011 |
![]() |
192.168.7.3 is a client device in 192.168.7.1/24 network, where 192.168.7.1 is gateway.
Request who-has 192.168.7.3 tell 192.168.7.3, length 28 Request who-has 192.168.7.3 tell 192.168.7.3, lengt ... |
|
![]() |
|
![]() |
|
MonarchX Replies: 13 Views: 2794 |
![]() |
I spent half a day figuring out why EBTables were killing off my WiFi - 0x888E (EAP over LAN) had to be accepted for WiFi to work. | |
![]() |
|
![]() |
|
MonarchX Replies: 13 Views: 2794 |
![]() |
I don't use DHCP for LAN and assign static IP to each LAN device. I also assign and apply static ARP on-boot for each LAN devices in router and in LAN DNS server. My EBTables rules do not allow for A ... | |
![]() |
|
![]() |
|
MonarchX Replies: 13 Views: 2794 |
![]() |
My RP has only 1 loopback interface and 1 Ethernet interface. It does not have any bridge (br0) interfaces. It connects to one of my router's Ethernet ports and shows up in my router's ARP table as a ... | |
![]() |
|
![]() |
|
MonarchX Replies: 13 Views: 2794 |
![]() |
Isn't EBTables supposed to work only for bridge interfaces? If such is the the case, then EBTables rules for my Raspberry Pi (which has only one interface) should have no effect, but they do... | |
![]() |
|
![]() |
|
MonarchX Replies: 4 Views: 919 |
![]() |
This is a bit off-topic, but when reading examples of anti-spoofing rules, examples mostly include source forwarding rules. Shouldn't anti-spoofing rules cover all directions? EBTables support syntax ... | |
![]() |
|
All times are GMT |