Re: Vlans

Bart De Schuymer <[email protected]> Sat, 04 Nov 2006 19:59:09 +0100
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Op do, 02-11-2006 te 11:19 +0100, schreef Lutz Jaenicke:

> > That would be interesting, thanks. I was thinking about a userspace flag
> > like --vlan-encapsulated to let the user specify she wants to filter the
> > ip/arp/etc stuff inside the vlan package. The kernel logic best resides
> > inside the specific matches/targets, shouldn't be too messy.
> 
> I had implemented it using a /proc/sys control flag as attached
> below. I am not to happy with this solution, so if you have a better
> proposal...

The option --vlan-encapsulated (or perhaps --vlan-transparent is better)
can be implemented using the struct ebt_entry bitmask field. The only
thing that needs to be changed in your kernel patch is using this
bitmask field instead of ebtables_treat_vlan_transparent. The userspace
tool will need to be altered too, of course.
This way, the user can choose to make vlan transparent or not for
specific rules instead of making it globally transparent or not.

cheers,
Bart



-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642