[Ilugc] Re: A short networking tutorial
- From: mohan.tux@xxxxxxxxx (Mohan Sundaram)
- Date: Sun Oct 28 09:25:23 2007
Girish Venkatachalam wrote:
Reason is simple. It is stupid to have two interfaces have the same
network address/subnet mask. Why would you do that? You can eminently
use aliases for adding as many IP addresses in as many network ranges
you want on a single physical interface.
One area where I used this prior to DNAT arrival in iptables was to
assign the same IP address to two interfaces, creating different routing
tables for packets that arrive at different interfaces, iptables for
filtering thereby creating a routed pseudo bridged firewall with a DMZ
carrying public IP addresses.
ebtables arrived pretty recently (2003) till when that was relevant. I
do agree that it has lost most of its relevance in recent times and
avoiding this makes for clean segregated networks.
Mohan
Other related posts: