Filtering bridge is not router, so it's not realy important what subnets and
how many are on each end of bridge.
Use recomended (and documented) transparent bridge configurations with
WAN-OPT1 bridging and get things working. Be carefull with predifined rules
(block private networks), not to interfere with your setup.
Mono's IP on WAN can be of any subnets you connect to (or ip-less if you
want), but mono's IP on LAN shoudn't be in those subnets, if you want to
keep things simple.
Maybe your LAN is connected to the wrong "place". I didn't find anything to
imply where goes your m0n0's LAN connection.
----- Original Message -----
From: "Holger Bauer" <Holger dot Bauer at citec dash ag dot de>
To: <m0n0wall at lists dot m0n0 dot ch>
Sent: Wednesday, December 14, 2005 12:12 PM
Subject: [m0n0wall] Filtering Bridge blocking traffic for clients with
I want to setup a transparent filtering bridge. This device only should
trafficshaping and nothing else. I have set up this in the past with success
I'm running multiple locations with that kind of setup. However I now have
install filtering bridges at a location where Clients have multiple IP
(at the same physical NIC) from different subnets:
I tried bridging WAN to OPT1 and later LAN to OPT1. Rules at all interfaces
any protocol, any source, any destination, allow fragmented packets.
is enabled at advanced settings.
If the m0n0s IP at the interface the other one is bridged to is in the range
all 10.1.1.x/24 traffic is blocked. If the IP of the m0n0 is something like
192.168.1.x/24 traffic is blocked (entries in the firewall logs). It appears
that all non
m0n0-range IPs are always blocked.
Replacing the m0n0-bridge with a cable makes the connection happy again. Any
Thanks for any suggestions,
Virus checked by G DATA AntiVirusKit
To unsubscribe, e-mail: m0n0wall dash unsubscribe at lists dot m0n0 dot ch
For additional commands, e-mail: m0n0wall dash help at lists dot m0n0 dot ch