On 16.01.2010 18:37, Daniel Drake wrote: > At first glance it looks ideal, but after trying to get it working, it > seems inappropriate. > Setting all ebtables policies to DROP (and adding log rules) does > nothing. As far as I can tell, ebtables only operates on bridge > devices, of which there are none in this setup. Am I missing anything? Create a bridge with only one enslaved device and ebtables should see the traffic: http://ebtables.sourceforge.net/examples/basic.html#ex_nobridge -- Eray -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html