I'm experimenting with a dual NIC box running Squid, Privoxy and PF packet filter on it.
I've learned, that packet filters are ultimate safe, when they are transparent between two interfaces showing no IP to either side, which is called a bridged firewall. Now correct me, if I'm wrong, but such a bridge could be given an IP-adress on one interface for setting it up and maintaining it (which of course would make it attackable, at least temporarily as long as an IP is setup and enabeled)? Or in other words: can an interface which is set up as a bridge, have a IP-adress on one side?
If this is possible, I might go a step further: I like to know if is possible running additional appliances on a box primarily set up as a bridge? I. E. can privoxy and squid run on it too, when running each in a jail with an IP?
Any hints are welcome, adding some surplus to a plain bridged firewall.
I've learned, that packet filters are ultimate safe, when they are transparent between two interfaces showing no IP to either side, which is called a bridged firewall. Now correct me, if I'm wrong, but such a bridge could be given an IP-adress on one interface for setting it up and maintaining it (which of course would make it attackable, at least temporarily as long as an IP is setup and enabeled)? Or in other words: can an interface which is set up as a bridge, have a IP-adress on one side?
If this is possible, I might go a step further: I like to know if is possible running additional appliances on a box primarily set up as a bridge? I. E. can privoxy and squid run on it too, when running each in a jail with an IP?
Any hints are welcome, adding some surplus to a plain bridged firewall.