From: Hangbin Liu <liuhangbin@gmail.com>
To: netdev@vger.kernel.org
Cc: "David S . Miller" <davem@davemloft.net>,
David Ahern <dsahern@kernel.org>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Ido Schimmel <idosch@idosch.org>,
Nikolay Aleksandrov <razor@blackwall.org>,
Roopa Prabhu <roopa@nvidia.com>,
Stephen Hemminger <stephen@networkplumber.org>,
Florian Westphal <fw@strlen.de>, Andrew Lunn <andrew@lunn.ch>,
Florian Fainelli <f.fainelli@gmail.com>,
Vladimir Oltean <olteanv@gmail.com>,
Jiri Pirko <jiri@resnulli.us>,
Marc Muehlfeld <mmuehlfe@redhat.com>,
Hangbin Liu <liuhangbin@gmail.com>
Subject: [PATCHv3 net-next 09/10] docs: bridge: add netfilter doc
Date: Tue, 28 Nov 2023 16:49:42 +0800 [thread overview]
Message-ID: <20231128084943.637091-10-liuhangbin@gmail.com> (raw)
In-Reply-To: <20231128084943.637091-1-liuhangbin@gmail.com>
Add netfilter part for bridge document.
Reviewed-by: Florian Westphal <fw@strlen.de>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
---
Documentation/networking/bridge.rst | 36 +++++++++++++++++++++++++++++
1 file changed, 36 insertions(+)
diff --git a/Documentation/networking/bridge.rst b/Documentation/networking/bridge.rst
index 3b82cf52bfec..06c2915211d8 100644
--- a/Documentation/networking/bridge.rst
+++ b/Documentation/networking/bridge.rst
@@ -234,6 +234,42 @@ kernel.
Please see the :ref:`switchdev` document for more details.
+Netfilter
+=========
+
+The bridge netfilter module is a legacy feature that allows to filter bridged
+packets with iptables and ip6tables. Its use is discouraged. Users should
+consider using nftables for packet filtering.
+
+The older ebtables tool is more feature-limited compared to nftables, but
+just like nftables it doesn't need this module either to function.
+
+The br_netfilter module intercepts packets entering the bridge, performs
+minimal sanity tests on ipv4 and ipv6 packets and then pretends that
+these packets are being routed, not bridged. br_netfilter then calls
+the ip and ipv6 netfilter hooks from the bridge layer, i.e. ip(6)tables
+rulesets will also see these packets.
+
+br_netfilter is also the reason for the iptables *physdev* match:
+This match is the only way to reliably tell routed and bridged packets
+apart in an iptables ruleset.
+
+Note that ebtables and nftables will work fine without the br_netfilter module.
+iptables/ip6tables/arptables do not work for bridged traffic because they
+plug in the routing stack. nftables rules in ip/ip6/inet/arp families won't
+see traffic that is forwarded by a bridge either, but that's very much how it
+should be.
+
+Historically the feature set of ebtables was very limited (it still is),
+this module was added to pretend packets are routed and invoke the ipv4/ipv6
+netfilter hooks from the bridge so users had access to the more feature-rich
+iptables matching capabilities (including conntrack). nftables doesn't have
+this limitation, pretty much all features work regardless of the protocol family.
+
+So, br_netfilter is only needed if users, for some reason, need to use
+ip(6)tables to filter packets forwarded by the bridge, or NAT bridged
+traffic. For pure link layer filtering, this module isn't needed.
+
FAQ
===
--
2.41.0
next prev parent reply other threads:[~2023-11-28 8:50 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-11-28 8:49 [PATCHv3 net-next 00/10] Doc: update bridge doc Hangbin Liu
2023-11-28 8:49 ` [PATCHv3 net-next 01/10] docs: bridge: update doc format to rst Hangbin Liu
2023-11-28 22:46 ` Stephen Hemminger
2023-11-29 7:34 ` Hangbin Liu
2023-11-29 4:16 ` Florian Fainelli
2023-11-28 8:49 ` [PATCHv3 net-next 02/10] net: bridge: add document for IFLA_BR enum Hangbin Liu
2023-11-29 18:37 ` Vladimir Oltean
2023-11-28 8:49 ` [PATCHv3 net-next 03/10] net: bridge: add document for IFLA_BRPORT enum Hangbin Liu
2023-11-28 8:49 ` [PATCHv3 net-next 04/10] docs: bridge: Add kAPI/uAPI fields Hangbin Liu
2023-11-28 22:47 ` Stephen Hemminger
2023-11-29 4:11 ` Florian Fainelli
2023-11-28 8:49 ` [PATCHv3 net-next 05/10] docs: bridge: add STP doc Hangbin Liu
2023-11-28 22:48 ` Stephen Hemminger
2023-11-29 7:43 ` Hangbin Liu
2023-11-29 15:10 ` Stephen Hemminger
2023-11-29 18:46 ` Vladimir Oltean
2023-11-29 4:21 ` Florian Fainelli
2023-11-29 18:48 ` Vladimir Oltean
2023-11-28 8:49 ` [PATCHv3 net-next 06/10] docs: bridge: add VLAN doc Hangbin Liu
2023-11-29 4:12 ` Florian Fainelli
2023-11-29 18:40 ` Vladimir Oltean
2023-11-28 8:49 ` [PATCHv3 net-next 07/10] docs: bridge: add multicast doc Hangbin Liu
2023-11-29 4:15 ` Florian Fainelli
2023-11-28 8:49 ` [PATCHv3 net-next 08/10] docs: bridge: add switchdev doc Hangbin Liu
2023-11-29 4:16 ` Florian Fainelli
2023-11-28 8:49 ` Hangbin Liu [this message]
2023-11-29 4:18 ` [PATCHv3 net-next 09/10] docs: bridge: add netfilter doc Florian Fainelli
2023-11-28 8:49 ` [PATCHv3 net-next 10/10] docs: bridge: add other features Hangbin Liu
2023-11-29 4:09 ` Florian Fainelli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20231128084943.637091-10-liuhangbin@gmail.com \
--to=liuhangbin@gmail.com \
--cc=andrew@lunn.ch \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=f.fainelli@gmail.com \
--cc=fw@strlen.de \
--cc=idosch@idosch.org \
--cc=jiri@resnulli.us \
--cc=kuba@kernel.org \
--cc=mmuehlfe@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=olteanv@gmail.com \
--cc=pabeni@redhat.com \
--cc=razor@blackwall.org \
--cc=roopa@nvidia.com \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.