"James Knott" <(E-Mail Removed)> wrote in message news:7P-dnQRSK5ITeg7cRVn-(E-Mail Removed)...
>
> It won't work. When Linux determines that both sides are on the same wire,
> it will send an ICMP redirect, telling the computer to talk directly to the
> modem etc. Remember, local communications don't use an IP. They use a mac
> address, so your firewall will become invisible.
OK.
I found a bridge/firewall setup at
http://www.shorewall.net
If I understood it correctly, a bridge basically works as a
switch inside the LAN. So with a bridge I would not even have
to reconfigure the hosts on the LAN, just stick the bridge
in between somewhere. And if the bridge stops working for some
reason, (or some admin doesn't like it,) it can simply be
unplugged and bypassed with a cable.
Mats