>There is a also the caveat:  The switch will probably _not_ forward the STP
BPDU's from one port to another. 

You were correct -- my initial testing confirmed this. Would the same issue
arise if I employed a gateway IP on the /bridge/ instead, and used CARP as a
failover mechanism? The firewall no longer becomes transparent pass
through/firewall. I have not done carp with bridges and I'm not 100% certain
the same STP forwarding problems wouldn't arise, even with an IP assigned.

Such as :

[switch 1 (vlan 1)]
   |       |
 [fw1 gw1] -- CARP -- [fw2 gw1]
   |       |
[switch 1 (vlan 2)]


Thanks,

Kevin


_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"

Reply via email to