Re: [VLAN] how to filter tagged frames of different vlanid in one bridge?

Nick Fedchik <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Organization UkrSat
Message-ID <[email protected]>
Hello zhengchuanbo,
Wednesday, January 8, 2003, 3:43:22, you wrote:
z> we use linux as our firewall. the firewall worked at bridge mode.
z> it is connected to the trunk port of the switch. what we want to do
z> is to filter the vlan tagged frames(802.1Q) by ip address.i
z> tried two methods:
        
z> 1.by ebtables
z> ebtables can filter 802.1Q protocol. but it can not filter by ip
z> address. it can only filter the ip address when the protocol is
z> IPV4.
It's in my TODO, but I so busy now and haven't time left to do that.

z> i wish i could do the job by ebtables.
Subscribe and mail to [email protected]
if You can help me to do that.

z> 2.by bridge-nf patch and vconfig
...
z> after i applied the patch bridge-nf, netfilter works for the vlan
z> frames. the problem is we have many vlans(more than ten).
z> so i have to build a bridge for all the vlans.
AFAIK here the problem of big mem usage by keeping a lot of vlan-aware
interfaces, IADM.

z> is there some solution to that?
I don't know any complete solutions for this topic.

-- 
Best regards,
Nick Fedchik FNM3-RIPE
Senior Engineer, Internet Dept/UkrSat ISP, Ukraine, Kiev



-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.