All of lore.kernel.org
 help / color / mirror / Atom feed
* [Bridge] Clarification regarding device matches in bridge-netfilter
@ 2006-12-05 12:37 Tino Keitel
  2006-12-05 17:13 ` Tino Keitel
  2006-12-05 17:19 ` Stephen Hemminger
  0 siblings, 2 replies; 3+ messages in thread
From: Tino Keitel @ 2006-12-05 12:37 UTC (permalink / raw)
  To: bridge

Hi folks,

in 2.4 kernels, device matching for bridged packets was done with
iptables -i/-o. Since 2.6, I was used to use -m physdev here.

In 2.6.18, This seems to be more complicated. At least the filter/INPUT
chain now doesn't match with -m physdev --physdev-in anymore, but
FORWARD and OUTPUT does. I also read the note that -m phydev is now
deprecated for non-bridged traffic.

Does this mean that

1. I have to use the physdev match for bridged traffic, e.g. FORWARD,
   POSTROUTING, PREROUTING

2. I have to use iptables -i in the INPUT chain and on PREROUTING

3. I have to use the physdev match in the OUTPUT chain

4. I have to distinguish between bridged and locally processed or
   routed traffic in PREROUTING, since bridged traffic needs -m
   physdev, whereas the other traffic need -i

5. until now, outgoing traffic is always matched with -m physdev, but
   this will change in the future. If the change is made, I'll have to
   distinguish in the same way as for incoming traffic

Regards,
Tino

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2006-12-05 17:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-12-05 12:37 [Bridge] Clarification regarding device matches in bridge-netfilter Tino Keitel
2006-12-05 17:13 ` Tino Keitel
2006-12-05 17:19 ` Stephen Hemminger

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.