Dear Lev, On Sunday 26 of April 2020 14:07:08 Lev R. Oshvang . wrote: > >From my google search I did not find any netfilter /iptable rule which > > allows to filter on CAN fields, message ID and other. > Please point me in the right direction. I am not sure if this can help, but Rostislav Lisovy has implemented linux-devel/net/sched/em_canid.c which has been merged around Linux kernel version 3.6 and is still there. It allows to classify CAN frames for purpose of queening disciplines. There is report with documentation how to use it https://rtime.felk.cvut.cz/can/socketcan-qdisc-final.pdf I am not sure if this can be used for netfilter. For sure CAN Gateway allows separation of real and virtual can network and full control on IDs which are passed. Best wishes, Pavel -- Pavel Pisa phone: +420 603531357 e-mail: pisa@xxxxxxxxxxxxxxxx Department of Control Engineering FEE CVUT Karlovo namesti 13, 121 35, Prague 2 university: http://dce.fel.cvut.cz/ personal: http://cmp.felk.cvut.cz/~pisa projects: https://www.openhub.net/accounts/ppisa CAN related:http://canbus.pages.fel.cvut.cz/