Author |
Message |
|
Post subject: Filtrovanie broadcastov
Posted: 21.10.2004 - 19:43 #12355
|
|
Guru
Joined: Jan 30, 2003
Posts: 1572
|
|
chcel by som poprosit gurus, aby mi pomohli vytvorit pomocou iptables filter na filtrovanie broadcastov
konfiguracia
- - - - -wlan0 ROUTER eth0 ----- switch -----users
tzn. chcem aby od users neprechadzali ziadne broadcasty (pokial je to mozne)
thanks |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 00:19 #12371
|
|
Majster
Joined: Feb 25, 2003
Posts: 2606
Location: BA,BB
|
|
broadcasty sa neforwarduju (neroutuju) takze vlastne nemusis filtrovat nic v tomto pripade => cez ten router neprejdu aj keby tam nebol ziadny firewall |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 01:38 #12373
|
|
Majster
Joined: Feb 05, 2003
Posts: 2686
Location: Topolcany
|
|
ja dokonca tvrdim ze velku cast z nich uz odfiltruje switch aj ked si sa zase so mnou bude handrkovat;o) |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 01:49 #12374
|
|
Guru
Joined: Feb 19, 2003
Posts: 1133
Location: blizko Trencina
|
|
pre uplnost ...
$IPTABLES -A INPUT -m addrtype --src-type BROADCAST -j ACCEPT
atd.
typy si vygooglite .. |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 02:38 #12375
|
|
Majster
Joined: Feb 25, 2003
Posts: 2606
Location: BA,BB
|
|
jmi: na input-e na routri to ma zmysel filtrovat, ale len z hladiska routra, pretoze broadcasty nie su forwardovane dalej
fleg: iba ak manazovatelny |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 08:08 #12377
|
|
Majster
Joined: Okt 22, 2003
Posts: 3321
Location: Banská Bystrica - Rudlová
|
|
Kiwi ja som mal zas presne opacny problem ... chel som preniest bludne adresy cez router ... ale ako eXplorer napisal... cez router ti neprejdu, takze kofola. |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 22.10.2004 - 13:18 #12380
|
|
Guru
Joined: Feb 19, 2003
Posts: 1133
Location: blizko Trencina
|
|
tos ja som to uviedol len ako priklad .. samo o sebe to zmysel nedava a nema sa o tom zmysel bavit |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 23.10.2004 - 09:07 #12394
|
|
Guru
Joined: Jan 30, 2003
Posts: 1572
|
|
dobre, skusim inak, nemali ste niekedy problemy s broadcast storm? |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 03.11.2004 - 01:48 #12618
|
|
Basic
Joined: Feb 07, 2003
Posts: 136
|
|
fleq pokial ja viem tak switch nema dovod filtrovat broadcasty pokial sa jedna o nemanagovatelny switch s vlan pricom v tom pripade by to aj tak vsetko prechadzalo cez router....mohol by si to dajel rozpisat? mozno by s toho mohla byt zaujimava debata.
m. |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 03.11.2004 - 09:20 #12624
|
|
Majster
Joined: Feb 05, 2003
Posts: 2686
Location: Topolcany
|
|
kedysi som sa tu hadal (takmer so vsetkymi a hlavne si sickom) ze ci na par klientov staci ap a switch alebo tam treba router. vyslovil som hypotezu ze staci switch lebo ti klienti tu radiovu linku nezabiju ked si daju napr nieco medzi sebou kopirovat. niekto mi to vtedyu dosvedcil ze do radiovej linky slo len 5% broadcastov co povazujem za celkom slusny filtering. ale kde je ten thread sa mi hladat nechce;o) |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 03.11.2004 - 17:16 #12631
|
|
Guru
Joined: Jan 30, 2003
Posts: 1572
|
|
nerozumiem, odkial islo len 5% broadcastov?
co sa tyka zabitia linky pri kopirovani medzi klientmi jedneho AP, tak podla mojich skusenosti ju spolahlivo zabiju hocikedy
za zabitie povazujem uz to, ked latencie stupnu z 30ms na 600ms |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 03.11.2004 - 18:47 #12637
|
|
Guru
Joined: Feb 19, 2003
Posts: 1133
Location: blizko Trencina
|
|
ja za zabitu linku povazujem latencie 30ms
lebo ked mas take linky 2 v ceste, tak sa uz cez to neda hrat |
|
|
|
|
|
|
Post subject: RE: Filtrovanie broadcastov
Posted: 03.11.2004 - 20:06 #12640
|
|
Guru
Joined: Jan 30, 2003
Posts: 1572
|
|
iste je lepsie mat 5ms latencie, ale niekedy sa neda dostat na druhy koniec mesta bez 30ms
Ale garantujem, ze ked si zacnu dvaja useri kopirovat film, tak latencie vyletia hodne vysoko a vlastne len preto ze tam nie je shaper, ktory by to usmernil medzi urcite mantinely. |
|
|
|
|
|
|
Powered by PNphpBB2 © 2003-2005 The PNphpBB Group Credits |