On Mon, Mar 26, 2012 at 10:23:26PM +0200, Florian Westphal wrote: > If net.bridge.bridge-nf-filter-vlan-tagged is on, bridge > netfilter will remove skbs vlan header, then feeds the packet > to ip(6)tables. > > This changes the in/out interface to the vlan interface; if such > an interface has been configured, to allow iptables rules to > determine the original vlan the packet arrived on (e.g. > -i br0.1 will now work if a br0.1 vlan exists on top of br0 bridge > interface). Bart, can you see any problem with this approach? -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html