All of lore.kernel.org
 help / color / mirror / Atom feed
* NDv6 and xdp-filter
@ 2020-09-22  2:27 Topi Wala
  2020-09-22 11:28 ` Toke Høiland-Jørgensen
  0 siblings, 1 reply; 2+ messages in thread
From: Topi Wala @ 2020-09-22  2:27 UTC (permalink / raw)
  To: xdp-newbies

Hi,

I've installed an xdp-filter (dny_all) on my tap interface (and am
only letting through L2 packets that match my src/dst mac), and it
still lets through NDv6 traffic. Do L2 multicast packets not get
"received" by the xdp filter? Running tcpdump inside Qemu linux
connected to this tap interface shows me NDv6 multicast packets from
the ToR switch.

Thanks,
Hari

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: NDv6 and xdp-filter
  2020-09-22  2:27 NDv6 and xdp-filter Topi Wala
@ 2020-09-22 11:28 ` Toke Høiland-Jørgensen
  0 siblings, 0 replies; 2+ messages in thread
From: Toke Høiland-Jørgensen @ 2020-09-22 11:28 UTC (permalink / raw)
  To: Topi Wala, xdp-newbies

Topi Wala <walatopi@gmail.com> writes:

> Hi,
>
> I've installed an xdp-filter (dny_all) on my tap interface (and am
> only letting through L2 packets that match my src/dst mac), and it
> still lets through NDv6 traffic. Do L2 multicast packets not get
> "received" by the xdp filter? Running tcpdump inside Qemu linux
> connected to this tap interface shows me NDv6 multicast packets from
> the ToR switch.

All packets should be received by the XDP program; but only in the
ingress direction. So what do mean "running tcpdump inside the qemu
instance"? That sounds like you're talking about packets going *out* of
the TAP interface from the host PoV? XDP won't see those (you'll have to
run the program on the physical interface).

-Toke


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2020-09-22 11:28 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-09-22  2:27 NDv6 and xdp-filter Topi Wala
2020-09-22 11:28 ` Toke Høiland-Jørgensen

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.