From owner-freebsd-stable@FreeBSD.ORG Wed Oct 31 21:27:09 2007 Return-Path: Delivered-To: freebsd-stable@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D5C2716A417; Wed, 31 Oct 2007 21:27:09 +0000 (UTC) (envelope-from brett@lariat.net) Received: from lariat.net (lariat.net [66.119.58.2]) by mx1.freebsd.org (Postfix) with ESMTP id 400A313C4A3; Wed, 31 Oct 2007 21:27:09 +0000 (UTC) (envelope-from brett@lariat.net) Received: from anne-o1dpaayth1.lariat.org (IDENT:ppp1000.lariat.net@lariat.net [66.119.58.2]) by lariat.net (8.9.3/8.9.3) with ESMTP id OAA15758; Wed, 31 Oct 2007 14:49:01 -0600 (MDT) Message-Id: <200710312049.OAA15758@lariat.net> X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Wed, 31 Oct 2007 14:48:57 -0600 To: Andrew Thompson From: Brett Glass In-Reply-To: <20071031202446.GB9947@heff.fud.org.nz> References: <200710282222.QAA01991@lariat.net> <200710301036.50789.nvass@teledomenet.gr> <200710310148.TAA25585@lariat.net> <20071031194334.GA7297@heff.fud.org.nz> <200710312014.OAA14886@lariat.net> <20071031202446.GB9947@heff.fud.org.nz> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Cc: freebsd-stable@FreeBSD.org, Nikos Vassiliadis Subject: Re: MFC requests for 6.3 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 31 Oct 2007 21:27:09 -0000 At 02:24 PM 10/31/2007, Andrew Thompson wrote: >See >http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/net/if_bridge.c?only_with_tag=RELENG_6 Thank you for pointing this out.... Yes, I do see code that discards packets when a flag called IFBIF_PRIVATE is set. This is primarily what we need. As you can guess from this and other requests, I'm looking to revise the configuration on some specialized networking boxen so that NAT, bandwidth control, and LAN isolation are handled in the kernel rather than in user space. --Brett Glass