Project Description

FreeBSD lacks sophisticated layer2 and mixed layer2-layer3 filtering. ipfw performs mixed layer2-layer3 packet filtering using its own hooks in ether_demux/ether_output_frame and if_bridge. pf can't filter by layer2 addresses. I propose to improve both ipfw and pf to filter by layer2 addresses.

Recent patches can be found in github repository

Perforce repository: http://perforce.freebsd.org/changeList.cgi?CMD=changes&FSPC=//depot/projects/soc2008/gk%5fl2filter/...

Blog

Milestones

general

ipfw

pf

GlebKurtsov/Improving_layer2_filtering (last edited 2020-12-27T06:43:40+0000 by SashaVigole)