When one wants to use iptables (e.g. to control trafic between internal intefaces which is not possible with the AVM firewall), what use could/should the AVM firewall have?
The dslinterface its external IP-address is not shown with ifconfig, an interface named dsl with a local address is shown though (defined in ar7.cfg::dslinterface (ipaddr or dstipaddr?)). Does this mean iptables cannot control the interface to the internet and that the AVM firewall should handle this interface or can iptables refer to this strange interface?
Should NAT be provided by the AVM firewall or with iptables?
Should QOS be handled by the AVM firewall or iptables? (the FB provides telephony on a SIP account).
Do these firewalls interfere with one another?
A lot of questions, but maybe someone with a better understanding of the AVM firewall may be able to shed a light on this issue.
A little background. At the moment the FB runs in ata mode with LAN1 connected a separate ADSL modem (in bridging mode), but I also consider to have the FB handle the ADSL line. Ideally, the switch would be set such that each LAN port is a separate device, any bridging of internal interfaces would be accomplished with brctl or by declaring such bridged device in ar7.cfg.
The dslinterface its external IP-address is not shown with ifconfig, an interface named dsl with a local address is shown though (defined in ar7.cfg::dslinterface (ipaddr or dstipaddr?)). Does this mean iptables cannot control the interface to the internet and that the AVM firewall should handle this interface or can iptables refer to this strange interface?
Should NAT be provided by the AVM firewall or with iptables?
Should QOS be handled by the AVM firewall or iptables? (the FB provides telephony on a SIP account).
Do these firewalls interfere with one another?
A lot of questions, but maybe someone with a better understanding of the AVM firewall may be able to shed a light on this issue.
A little background. At the moment the FB runs in ata mode with LAN1 connected a separate ADSL modem (in bridging mode), but I also consider to have the FB handle the ADSL line. Ideally, the switch would be set such that each LAN port is a separate device, any bridging of internal interfaces would be accomplished with brctl or by declaring such bridged device in ar7.cfg.