Maxime Villard
2020-07-11 08:30:07 UTC
Any reason this isn't enabled by default? Right now you need to recompile
your kernel with "options BRIDGE_IPF" if you want a firewall on the bridge.
This is annoying.
There is already a dynamic switch behind it anyway: you need to pass "ipf"
to brconfig in order for filtering to actually be enabled, so having the
extra "options BRIDGE_IPF" serves little purpose.
I want to enable BRIDGE_IPF by default, by removing the option and the
#ifdefs. That is, by making the code part of bridge(4) by default.
Note that BRIDGE_IPF is not related to IPF. It uses the pfil interface, so
it works with NPF.
Maxime
--
Posted automagically by a mail2news gateway at muc.de e.V.
Please direct questions, flames, donations, etc. to news-***@muc.de
your kernel with "options BRIDGE_IPF" if you want a firewall on the bridge.
This is annoying.
There is already a dynamic switch behind it anyway: you need to pass "ipf"
to brconfig in order for filtering to actually be enabled, so having the
extra "options BRIDGE_IPF" serves little purpose.
I want to enable BRIDGE_IPF by default, by removing the option and the
#ifdefs. That is, by making the code part of bridge(4) by default.
Note that BRIDGE_IPF is not related to IPF. It uses the pfil interface, so
it works with NPF.
Maxime
--
Posted automagically by a mail2news gateway at muc.de e.V.
Please direct questions, flames, donations, etc. to news-***@muc.de