On 5 Jan 2011, at 12:12, Jonathan Tripathy wrote: > > If I plug my Xen host to a VLAN aware switch using a trunk port (I.e. all frames are tagged), can my Xen host, using a linux bridge, strip out all tagging and send frame to correct Xen VM? (And vice versa) Yes. The outgoing interface on the bridge deals with the VLAN tag. > > I wish to have isolated and secure networks that cannot communicate except via my VLAN aware firewall (pfsense) Yup, that's what you get. jch-- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html