Re: [VLAN] how to filter tagged frames of different vlanid in one bridge?
Nick Fedchik <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Organization | UkrSat |
| Message-ID | <[email protected]> |
Hello zhengchuanbo,
Wednesday, January 8, 2003, 3:43:22, you wrote:
z> we use linux as our firewall. the firewall worked at bridge mode.
z> it is connected to the trunk port of the switch. what we want to do
z> is to filter the vlan tagged frames(802.1Q) by ip address.i
z> tried two methods:
z> 1.by ebtables
z> ebtables can filter 802.1Q protocol. but it can not filter by ip
z> address. it can only filter the ip address when the protocol is
z> IPV4.
It's in my TODO, but I so busy now and haven't time left to do that.
z> i wish i could do the job by ebtables.
Subscribe and mail to [email protected]
if You can help me to do that.
z> 2.by bridge-nf patch and vconfig
...
z> after i applied the patch bridge-nf, netfilter works for the vlan
z> frames. the problem is we have many vlans(more than ten).
z> so i have to build a bridge for all the vlans.
AFAIK here the problem of big mem usage by keeping a lot of vlan-aware
interfaces, IADM.
z> is there some solution to that?
I don't know any complete solutions for this topic.
--
Best regards,
Nick Fedchik FNM3-RIPE
Senior Engineer, Internet Dept/UkrSat ISP, Ukraine, Kiev
-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com