The problem with your approach is that it adds a hash lookup in the packet process critical path. Also the concept of different filters for egress vs ingress is feature madness. It doesn't make sense to have half-duplex connectivity.
The problem with your approach is that it adds a hash lookup in the packet process critical path. Also the concept of different filters for egress vs ingress is feature madness. It doesn't make sense to have half-duplex connectivity.