Re: Vlans

Lutz Jaenicke <[email protected]> Wed, 18 Oct 2006 20:01:46 +0200
Newsgroups gmane.linux.network.bridge.ebtables.user
Organization Innominate Security Technologies AG
Message-ID <[email protected]>
On Wed, Oct 18, 2006 at 03:19:51PM +0000, Julien VARLET wrote:
> Hi,
> 
> I read that ebtables can do vlan filtering. I would like to have this configuration :
> switch (VLANs) <--> bridge filtering <--> switch (VLANs)
> 
> I would like to know if ebtables is vlans transparent for 802.1Q by default.

The bridge netfilter component (rules configured via iptables command) is
transparent wrt VLAN tagging. The firewall rules are applied regardless
of VLAN tagging.
The ebtables components (those configured with the ebtables command)
can be used to filter for VLAN tags. The ebtables specific protocol
matchers for arp, ip, etc are not transparent wrt VLAN: they will
not match VLAN encapsulated traffic. Note: I do have an extension
patch to provide this support (configurable) for some really old
version of ebtables (for kernel 2.4 with br-nf patch) that is due
to be ported to 2.6.18+ in the next days anyway.
I can send it to the list for discussion/inclusion as soon as the
porting is done if there is interest...

Best regards,
	Lutz
-- 
Dr.-Ing. Lutz Jänicke
CTO
Innominate Security Technologies AG  /protecting industrial networks/
tel: +49.30.6392-3308
fax: +49.30.6392-3307
Albert-Einstein-Str. 14
D-12489 Berlin, Germany
www.innominate.com

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642