net.link.bridge.ipfw_arp/net.link.ipfw: filtering only with IPFW?

O. Hartmann ohartman at zedat.fu-berlin.de
Fri Mar 16 10:39:13 UTC 2007


This question may sound stupid, but I would like to ask it anyway.

On my lab's and private's FreeBSD box (lab is FBSD 6.2-STABLE, at home 
7.0-CURRENT) I utilize pf() as my preferred filtering system.

What is the meaning of net.link.bridge.ipfw_arp and 
net.link.bridge.ipfw? Does it mean it can only be filtered by ipfw() or 
is this simply a global meaning that each bridged packet is injected 
into any filtering facility? I'm not very firm with MAC based filtering, 
I only know ipfw() is/was capable of doing that, but is pf() also? A 
sneak look at the manpage doesn't revela that point for me, sorry for my 
lazyness.

Thanks for your patience,
Oliver



More information about the freebsd-questions mailing list