Re: Port Mirroring in Linux



On Oct 30, 5:07 am, jeniffer <zenith.of.perfect...@xxxxxxxxx> wrote:

thanks for the reply but No, I dont have to set up a bridge.A bridge
looks at its table's entry and says that packets with the mac 'Mi'
must be forwarding to interface X.Bridge does flooding,learning and
forwarding.

Right.

I need a behavior where I say that all packets coming and going on an
interface X must be given to another interface Y.

That's what a bridge does. As you said above, it looks at its table's
entry and decides which interfaces to forward a packet to.

You are saying:

1) A bridge takes a packet and forwards it onto the appropriate
interfaces.

2) I want to take packets and forward them to appropriate interfaces.

3) I don't want a bridge.

You do realize that bridges frequently send the same packet to more
than one destination. Consider the obvious case where the bridge has
never seen a packet with that destination MAC before. Consider an ARP
request.

What you want is what bridges do.

DS

.



Relevant Pages

  • RE: Intrusion Prevention requirements document
    ... The tools consider one interface as "client" and other ... Packet 1 is first sent out on client interface. ... > my previous company was Blade Software where I developed IDS Informer ... Up to 75% of cyber attacks are launched on shopping carts, ...
    (Pen-Test)
  • Re: multiple routing tables review patch ready for simple testing.
    ... We could put a packet classifier into the kernel which works just fine for DOCSIS consumer distribution networks, but has absolutely no relevance to an ATM backbone. ... IS possible that an interface in the future might have a default ... For now, the limitations of the system should be documented so that users don't inadvertently configure local forwarding loops, even for unicast traffic; with multicast, the amplification effect of misconfiguration is inherently more damaging to a network. ... I see you tweaked verify_pathto do the lookup in the numbered FIB. ...
    (freebsd-net)
  • Re: Pix 515 VLAN NAT0 issues
    ... that ACL will be exempt from NAT. ... the packet at the time the PIX receives the packet. ... ACL applied to an inside interface would have the internal IPs as ... accepted as having a translation and satisfying the security policies. ...
    (comp.dcom.sys.cisco)
  • Re: [ADVICE NEEDED] if_bridge and pfil hooks behaviour
    ... interface are destined to some bridge member at the layer 2. ... The current behaviour is the following: pfil hooks are getting the ... interface if the bridge for which the packet is destined. ...
    (freebsd-net)
  • RE: Intrusion Prevention requirements document
    ... The tools consider one interface as "client" and other ... Packet 1 is first sent out on client interface. ... > The product uses two network cards and so the library of over 700 ... > my previous company was Blade Software where I developed IDS Informer ...
    (Focus-IDS)