If memory serves me right, Manuel Kasper wrote:
> > One thing I've learned along the way is that the filtering bridge
> > feature that got me involved with m0n0wall in the first place is a
> > lot easier to implement and use with the new if_bridge(4) driver,
> > which was ported from OpenBSD. For starters, this makes it
> > possible to solve the "can't do NAT and bridging on the same box"
> > problem. It also integrates with PF (presumably other firewalls
> > too) fairly nicely.
>
> Yep, it'll be nice when the whole
> Filtering/NAT/Shaping/IPsec/Bridging mess can be untangled a little!
"Untangled" reminded me of the attached message. It's a good thing that
I didn't see this until well after I had a working filtering bridge,
otherwise I would have run away from the horror of it all. :-)
Cheers,
Bruce.
PS. It's for -CURRENT but I think it's applicable to RELENG_6, and
parts even for RELENG_5. |