Sponsored Content
Full Discussion: iptables - MAC routing
Special Forums IP Networking iptables - MAC routing Post 302893336 by DGPickett on Tuesday 18th of March 2014 03:20:08 PM
Old 03-18-2014
Sounds like something we did to avoid manual router config for odd IP destinations: add entries to the ARP server on any local host so packets to an additional IP device installed in a host on the local net would be directed on that host's local net IP/MAC. Once these packets rise through the ethernet layer into the IP Stack, it recognizes them as local and delivers them without IP forwarding.
 

4 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Routing or Iptables connections by hostname or ip address

edit; I found a solution that works, see thread #3 https://www.unix.com/302417065-post3.html Hi there, I have a small dedicated server that has four ip addresses and by default my httpd sends request using the servers main ip for all outbound connections. I'm quite amateur at routing and... (4 Replies)
Discussion started by: mooofa
4 Replies

2. Cybersecurity

Configure iptables to allows list of MAC address

Hi all, I want to make this nw diagram: Small NW ---(eth1)-- Linux iptables --(eth0)---LAN NW And with these requirements: 1. Allow only 1 Mac address aa-aa-aa-aa-aa-aa from Small NW to LAN NW 2. Allow list of Mac addresses from LAN NW access to Small NW What will I... (2 Replies)
Discussion started by: blackthu80
2 Replies

3. IP Networking

iptables specific ip routing via tun

hi guys! I was searching few days for a solution to my problem but haven't found one or I'm too dumb to understand. Here's what happened: I have a linux server used as a router. It has an eth0 and eth1 (local interface). I just installed openvpn (I need it only as a client), I configured it and... (0 Replies)
Discussion started by: shamora
0 Replies

4. UNIX for Dummies Questions & Answers

iptables / ip route packet routing with multiple gateways

Hi all. Linux noob here. I was hoping someone could help me with configuring some routing rules on my router, an Asus AC68. The router is connected to two gateways, wan0_gateway and wan1_gateway. I have rules set up in the router gui that will push all traffic from every IP other than my own... (0 Replies)
Discussion started by: Bishi
0 Replies
ARP(4)							   BSD Kernel Interfaces Manual 						    ARP(4)

NAME
arp -- Address Resolution Protocol SYNOPSIS
device ether DESCRIPTION
The Address Resolution Protocol (ARP) is used to dynamically map between Protocol Addresses (such as IP addresses) and Local Network Addresses (such as Ethernet addresses). This implementation maps IP addresses to Ethernet, ARCnet, or Token Ring addresses. It is used by all the Ethernet interface drivers. ARP caches Internet-Ethernet address mappings. When an interface requests a mapping for an address not in the cache, ARP queues the message which requires the mapping and broadcasts a message on the associated network requesting the address mapping. If a response is provided, the new mapping is cached and any pending message is transmitted. ARP will queue at most one packet while waiting for a response to a mapping request; only the most recently ``transmitted'' packet is kept. If the target host does not respond after several requests, the host is con- sidered to be down allowing an error to be returned to transmission attempts. Further demand for this mapping causes ARP request retransmis- sions, that are ratelimited to one packet per second. The error is EHOSTDOWN for a non-responding destination host, and EHOSTUNREACH for a non-responding router. The ARP cache is stored in the system routing table as dynamically-created host routes. The route to a directly-attached Ethernet network is installed as a ``cloning'' route (one with the RTF_CLONING flag set), causing routes to individual hosts on that network to be created on demand. These routes time out periodically (normally 20 minutes after validated; entries are not validated when not in use). ARP entries may be added, deleted or changed with the arp(8) utility. Manually-added entries may be temporary or permanent, and may be ``published'', in which case the system will respond to ARP requests for that host as if it were the target of the request. In the past, ARP was used to negotiate the use of a trailer encapsulation. This is no longer supported. ARP watches passively for hosts impersonating the local host (i.e., a host which responds to an ARP mapping request for the local host's address). Proxy ARP is a feature whereby the local host will respond to requests for addresses other than itself, with its own address. Normally, proxy ARP in FreeBSD is set up on a host-by-host basis using the arp(8) utility, by adding an entry for each host inside a given subnet for which proxying of ARP requests is desired. However, the ``proxy all'' feature causes the local host to act as a proxy for all hosts reach- able through some other network interface, different from the one the request came in from. It may be enabled by setting the sysctl(8) MIB variable net.link.ether.inet.proxyall to 1. MIB Variables The ARP protocol implements a number of configurable variables in net.link.ether.inet branch of the sysctl(3) MIB. allow_multicast Should the kernel install ARP entries with multicast bit set in the hardware address. Installing such entries is RFC 1812 violation, but some prorietary load balancing techniques require routers on network to do so. Turned off by default. log_arp_movements Should the kernel log movements of IP addresses from one hardware address to an other. See DIAGNOSTICS below. Turned on by default. log_arp_permanent_modify Should the kernel log attempts of remote host on network to modify a permanent ARP entry. See DIAGNOSTICS below. Turned on by default. log_arp_wrong_iface Should the kernel log attempts to insert an ARP entry on an interface when the IP network the address belongs to is connected to an other interface. See DIAGNOSTICS below. Turned on by default. max_log_per_second Limit number of remotely triggered logging events to a configured value per second. Default is 1 log message per second. max_age How long an ARP entry is held in the cache until it needs to be refreshed. Default is 1200 seconds. maxhold How many packets hold in the per-entry output queue while the entry is being resolved. Default is one packet. maxtries Number of retransmits before host is considered down and error is returned. Default is 5 tries. proxyall Enables ARP proxying for all hosts on net. Turned off by default. wait Lifetime of an incomplete ARP entry. Default is 20 seconds. DIAGNOSTICS
arp: %x:%x:%x:%x:%x:%x is using my IP address %d.%d.%d.%d on %s! ARP has discovered another host on the local network which responds to map- ping requests for its own Internet address with a different Ethernet address, generally indicating that two hosts are attempting to use the same Internet address. arp: link address is broadcast for IP address %d.%d.%d.%d! ARP requested information for a host, and received an answer indicating that the host's ethernet address is the ethernet broadcast address. This indicates a misconfigured or broken device. arp: %d.%d.%d.%d moved from %x:%x:%x:%x:%x:%x to %x:%x:%x:%x:%x:%x on %s ARP had a cached value for the ethernet address of the referenced host, but received a reply indicating that the host is at a new address. This can happen normally when host hardware addresses change, or when a mobile node arrives or leaves the local subnet. It can also indicate a problem with proxy ARP. This message can only be issued if the sysctl net.link.ether.inet.log_arp_movements is set to 1, which is the system's default behaviour. arpresolve: can't allocate llinfo for %d.%d.%d.%d The route for the referenced host points to a device upon which ARP is required, but ARP was unable to allocate a routing table entry in which to store the host's MAC address. This usually points to a misconfigured routing table. It can also occur if the kernel cannot allocate memory. arp: %d.%d.%d.%d is on if0 but got reply from %x:%x:%x:%x:%x:%x on if1 Physical connections exist to the same logical IP network on both if0 and if1. It can also occur if an entry already exists in the ARP cache for the IP address above, and the cable has been disconnected from if0, then reconnected to if1. This message can only be issued if the sysctl net.link.ether.inet.log_arp_wrong_iface is set to 1, which is the system's default behaviour. arp: %x:%x:%x:%x:%x:%x attempts to modify permanent entry for %d.%d.%d.%d on %s ARP has received an ARP reply that attempts to overwrite a permanent entry in the local ARP table. This error will only be logged if the sysctl net.link.ether.inet.log_arp_permanent_modify is set to 1, which is the system's default behaviour. arp: %x:%x:%x:%x:%x:%x is multicast Kernel refused to install an entry with multicast hardware address. If you really want such addresses being installed, set the sysctl net.link.ether.inet.allow_multicast to a positive value. SEE ALSO
inet(4), route(4), arp(8), ifconfig(8), route(8), sysctl(8) Plummer, D., "RFC826", An Ethernet Address Resolution Protocol. Leffler, S.J. and Karels, M.J., "RFC893", Trailer Encapsulations. BSD
November 5, 2013 BSD
All times are GMT -4. The time now is 02:42 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy