bridges with vlan member -- unicast?

Rudy crapsh at monkeybrains.net
Thu Feb 24 10:00:09 UTC 2011


Is anyone bridging a bunch (20+) vlans onto one bridge0?
My goal is to do what the HandBook says I can do:
The customers are completely isolated from each other, the full /24
address range can be allocated without subnetting.
http://www.freebsd.org/doc/handbook/network-bridging.html#AEN40688

Last time I tried this (8.1) I got a bunch of unicast flooding and it
busted my network.  I'd like to see a 'nounicast' flag for bridge members...

Say, I've never looked into it, but do unicast floods go to a broadcast
mac address (eg FF:FF:FF:FF:FF:FF) that I could block via layer2?
more on Unicast Flooding:
 http://packetlife.net/blog/2010/jun/4/blocking-unknown-unicast-flooding/

Rudy



More information about the freebsd-net mailing list