What's new

How does Netfilter handle BROUTE chain Link Layer data in Network Layer?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

SDF07S

Occasional Visitor
There is a way to use Netfilter EBTables BROUTE chain to force Link Layer data to go directly to Network Layer for filtering, but Link Layer can filter frames that Network Layer cannot. If I use BROUTE for LLDP frames, then what does Network Layer do with such frames? IPTables only works with Layer 3 packets and ARP. What can it possibly do with LLDP frames or any other Layer 2 information it receives? Here's the diagram:
YkwUi.png
 
Recall that LLDP is typically over the LAN only, and not forwarded...

It's a security risk to do so otherwise.
 
Similar threads

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top