Re: Vlans
Lutz Jaenicke <[email protected]> Wed, 18 Oct 2006 20:01:46 +0200
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Organization | Innominate Security Technologies AG |
| Message-ID | <[email protected]> |
On Wed, Oct 18, 2006 at 03:19:51PM +0000, Julien VARLET wrote: > Hi, > > I read that ebtables can do vlan filtering. I would like to have this configuration : > switch (VLANs) <--> bridge filtering <--> switch (VLANs) > > I would like to know if ebtables is vlans transparent for 802.1Q by default. The bridge netfilter component (rules configured via iptables command) is transparent wrt VLAN tagging. The firewall rules are applied regardless of VLAN tagging. The ebtables components (those configured with the ebtables command) can be used to filter for VLAN tags. The ebtables specific protocol matchers for arp, ip, etc are not transparent wrt VLAN: they will not match VLAN encapsulated traffic. Note: I do have an extension patch to provide this support (configurable) for some really old version of ebtables (for kernel 2.4 with br-nf patch) that is due to be ported to 2.6.18+ in the next days anyway. I can send it to the list for discussion/inclusion as soon as the porting is done if there is interest... Best regards, Lutz -- Dr.-Ing. Lutz Jänicke CTO Innominate Security Technologies AG /protecting industrial networks/ tel: +49.30.6392-3308 fax: +49.30.6392-3307 Albert-Einstein-Str. 14 D-12489 Berlin, Germany www.innominate.com ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642