Troubleshooting Linux Firewalls

ebtables (http://ebtables.sourceforge.net) is a filtering tool for an iptables/netfilter firewall running in bridge mode. It also has the ability to alter MAC addresses and route traffic at Layer 2. From the website, ebtables supports the following features:

  1. Ethernet protocol filtering

  2. MAC address filtering

  3. Simple IP header filtering

  4. ARP header filtering

  5. 802.1Q VLAN filtering

  6. In/Out interface filtering (logical and physical device)

  7. MAC address nat

  8. Logging Frame counters

  9. Ability to add, delete and insert rules; flush chains; zero counters

  10. brouter facility

  11. Ability to automatically load a complete table, containing the rules you made into the kernel

  12. Support for user defined chains

  13. Support for marking frames and matching marked frames

    Категории