OK, so as I understand it, the bridge does what I want (I really would prefer a single ip for administrative tasks, though there's probably other ways of doing it). The problem with a bridge is that it needs an ip, and for that, you need vether. At least, that's what I got from the faqs, which is why I went down that path to begin with:
(can't post urls - but search for vether in faq6)
...and here was me thinking the faqs were gospel...
The problem with my current set up (treating wireless and wired as separate subnets) is that while all devices connected to the ath0 interface can talk to each other and to the internet, they can't see the ethernet interfaces or anything connected to them.
More work to do...
Thanks again for your help
|