iptables - specifying iface that does not currently exist



Hi,

I've set up a router and firewall with iptables, the external link is a
ppp one using the speedtouch USB modem and the internal is a normal
ethernet card. The ppp link isn't always up, pppd will repeatedly try
until it gets through.

My question is: when the ppp0 iface goes down, what happens to the data
packets being forwarded out from the LAN to the internet? I have
ip_forward and ip_dynaddr both set to 1 and I know it's perfectly legal
to specify with iptables an iface that does not exist. But something
must be done to the packets being continuously sent into tho router
destined into a downed iface... Does the kernel buffer them up until
the link is back up (ip_dynaddr = 1)? wouldn't there be a limit for
this buffering? Should I turn off just the ip_forward and firewall with
the ip-down hook or is this unnecessary?

I need this router to be rock solid, with minimum maintainence as I
won't be able to administer it easily. hopefully someone can help me
out on this detail which I can't find any info on.

Cheers for any help received!

Justin

.



Relevant Pages

  • linux - iptable firewall DNS question
    ... When my firewall is active, i am unable to use name solving features from my ... iptables -P INPUT ACCEPT ... # $ipnet -> adresse ip de l'interface connectée à internet ... echo ACCES AU FIREWALL DEPUIS LOCAL ...
    (comp.security.firewalls)
  • Re: 3 LAN, 2 WAN - 2 LAN use 1 WAN, last LAN uses other WAN
    ... Internet over different paths after that. ... With a single LAN Router for all the segments, ... Then each "business" uses the Firewall they are supposed to use for the ...
    (microsoft.public.windows.server.networking)
  • Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet
    ... >It will be a while I get the router and do that. ... >> labelling on the box to be sure it has firewall features. ... name, like Disconnect from Internet, and click Finish. ... generally talking only about "critical patches" that affect security. ...
    (comp.security.firewalls)
  • Re: Networking problems with router between 2 p.c.s
    ... >> router for internet access. ... >> disable the internet connection firewall in the LAN ... isn't suitable for use on a local area network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Internet Connect of FC6..
    ... I was just borrowing a co-workers' ADSL internet connection to get some updates and get XGL working... ... Please see to it that iptables is ... I can recommend the router as a GP solution that will give you a much ...
    (Fedora)