<table cellspacing="0" cellpadding="0" border="0" ><tr><td valign="top" style="font: inherit;"><DIV>Hi,</DIV>
<DIV> </DIV>
<DIV>anbei mal meine Änderung von STP auf STP=yes (geht trotzdem nicht), weiterhin habe ich br0 anonymisiert. IPTLABES ist auch bei.</DIV>
<DIV> </DIV>
<DIV>Netzaufbau:</DIV>
<DIV> </DIV>
<DIV>Cisco router mirror port ----> eth2 / fra-fil server / eth3 -------> monitoring system</DIV>
<DIV> </DIV>
<DIV>Ich muss das Monitoring System entlasten und kann dies leider nicht im Cisco oder in dem Monitoring System selbst erledigen. </DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV>[root@fil-fra network-scripts]# cat ifcfg-br0<BR>DEVICE=br0<BR>TYPE=Bridge<BR>#IPADDR=192.168.10.2<BR>#NETMASK=255.255.255.0<BR>#BROADCAST=192.168.10.255<BR>#NETWORK=192.168.10.0<BR>STP=yes<BR>IPV6INIT=no<BR>ONBOOT=yes<BR>BOOTPROTO=none<BR></DIV>
<DIV>[root@fil-fra network-scripts]# brctl show<BR>bridge name bridge id STP enabled interfaces<BR>br0 8000.001b21520f78 yes eth3<BR> eth2<BR><BR>[root@fil-fra network-scripts]# iptables -L<BR>Chain INPUT (policy ACCEPT)<BR>target prot opt
source destination</DIV>
<DIV>Chain FORWARD (policy ACCEPT)<BR>target prot opt source destination<BR>ACCEPT tcp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 tcp dpt:XXX state NEW<BR>ACCEPT tcp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 tcp dpt:XXX state NEW<BR>ACCEPT udp -- anywhere anywhere PHYSDEV match
--physdev-in eth2 --physdev-out eth3 udp dpt:XXX state NEW<BR>ACCEPT udp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 udp dpt:XXX state NEW<BR>ACCEPT udp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 udp dpt:XXX state NEW<BR>ACCEPT udp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 udp dpt:XXX state NEW<BR>ACCEPT tcp --
anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 tcp dpt:XXX state NEW<BR>ACCEPT tcp -- anywhere anywhere PHYSDEV match --physdev-in eth2 --physdev-out eth3 tcp dpt:XXX state NEW<BR>ACCEPT all -- anywhere anywhere PHYSDEV match --physdev-is-bridged state RELATED,ESTABLISHED</DIV>
<DIV>Chain OUTPUT (policy ACCEPT)<BR>target prot opt source destination</DIV>
<DIV>Chain RH-Firewall-1-INPUT (0 references)<BR>target prot opt source destination<BR><BR>Jan</DIV>
<DIV> </DIV></td></tr></table><br>__________________________________________________<br>Do You Yahoo!?<br>Sie sind Spam leid? Yahoo! Mail verfügt über einen herausragenden Schutz gegen Massenmails. <br>http://mail.yahoo.com