Page MenuHomeVyOS Platform

Firewall bridge allways passes traffic to IP layer
Closed, ResolvedPublicFEATURE REQUEST


If firewall bridge is configured, traffic is always analyzed at IP layer too.
This is because currently sysctl parameter net.bridge.bridge-nf-call-iptables is set to 1

An option for editing this behavior/parameter needs to be included in firewall global-options


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible
Issue type
Improvement (missing useful functionality)

Event Timeline

n.fort changed the task status from Open to Confirmed.
n.fort changed Version from - to 1.5-rolling-202407100021.
dmbaturin triaged this task as Normal priority.Jul 15 2024, 6:34 AM
dmbaturin added a project: Restricted Project.
n.fort changed the task status from Confirmed to In progress.Jul 24 2024, 5:41 PM
n.fort moved this task from Need Triage to Backport Candidates on the VyOS 1.5 Circinus board.