EBTABLES(8) System Manager's Manual EBTABLES(8) (NAME) ebtables-nft - nftables (SYNOPSIS) ebtables [-t table ] -[ACDI] chain rule specification [match extensions] [watcher extensions] target ebtables [-t table ] -P chain ACCEPT | DROP | RETURN ebtables [-t table ] -F [chain] ebtables [-t table ] -Z [chain] ebtables [-t table ] -L [-Z] [chain] [ [--Ln] | [--Lx] ] [--Lc] [--Lmac2] ebtables [-t table ] -N chain [-P ACCEPT | DROP | RETURN] ebtables [-t table ] -X [chain] ebtables [-t table ] -E old-chain-name new-chain-name ebtables [-t table ] --init-table (DESCRIPTION) ebtables . iptables IP . (CHAINS) ebtables . . (chain) . . . <<>> (target) . . ( ) . . (TARGETS) . . : ACCEPT DROP CONTINUE RETURN <<>> ( ) . ACCEPT . DROP . BROUTING ACCEPT DROP ( -t ). CONTINUE . . RETURN () . (TARGET EXTENSIONS) . (TABLES) filter nat broute. filter . filter -t . -t ebtables . -t, --table filter : INPUT ( MAC ) OUTPUT ( / (b)routed) FORWARD ( ). nat MAC : PREROUTING ( ) OUTPUT ( (b)routed ) POSTROUTING ( ). PREROUTING POSTROUTING: PREFORWARDING POSTFORWARDING iptables ebtables . (-E) . broute brouter (-) : BROUTING. DROP ACCEPT broute ( ebtables-legacy ). DROP ACCEPT . BROUTING . . (OPTIONS) '-t table' ebtables . . (COMMANDS) ebtables -t . -t filter . -L -Z -N -P . -A, --append . -D, --delete . . ( -D). : start_nr[:end_nr] ( -L --Ln ). end_nr start_nr . -I . . ( ) . -C, --change-counters . . ( -C). : start_nr[:end_nr] ( -L --Ln ). -D . . ( ) . -C. . '+' . '-' . . '+' '-' . -I, --insert . . N -N N+1 . i i i-N-1 . 0 -A . 0 . -P, --policy . ACCEPT DROP RETURN . -F, --flush . . . -Z, --zero . . -Z -L . -Z -L . -L, --list . . -L : --Ln . --Lx . --Lc -L . (pcnt) (bcnt) . . --Lx '-c ' . --Lx ebtables . ( ) . ebtables . --Lx --Ln . --Lx --Lc '-c ' . --Lmac2 MAC . . -N, --new-chain . . . ACCEPT . -P -N . -P . -X, --delete-chain . () ebtables . . -E, --rename-chain . . PREFORWARDING PREROUTING -E PREROUTING . ebtables ebtables . ebtables ebtables . --init-table . (MISCELLANEOUS COMMANDS) -v, --verbose ( ). . -v . -V, --version ebtables. -h, --help [ ] . ebtables : ebtables -h snat log ip arp. list_extensions . -j, --jump . : ACCEPT DROP CONTINUE RETURN ( (TARGET EXTENSIONS) ) . -M, --modprobe . --concurrent ebtables . ebtables-nft . (RULE SPECIFICATIONS) ( ). "!" . . (MATCH EXTENSIONS) (WATCHER EXTENSIONS) . [!] -p, --protocol . 0x0600 ( ARP ) LENGTH . ( 802.2/802.3) . 0x0600 . . ebtables LENGTH . /etc/ethertypes . 0x0800 IPV4 . . . --proto . [!] -i, --in-interface ( ) ( INPUT FORWARD PREROUTING BROUTING ). '+' ( '+') . --in-if . [!] --logical-in () ( INPUT FORWARD PREROUTING BROUTING ). '+' ( '+') . [!] -o, --out-interface ( ) ( OUTPUT FORWARD POSTROUTING ). '+' ( '+') . --out-if . [!] --logical-out () ( OUTPUT FORWARD POSTROUTING ). '+' ( '+') . [!] -s, --source [/] MAC . . Unicast Multicast Broadcast BGA (Bridge Group Address) : Unicast=00:00:00:00:00:00/01:00:00:00:00:00, Multicast=01:00:00:00:00:00/01:00:00:00:00:00, Broadcast=ff:ff:ff:ff:ff:ff/ff:ff:ff:ff:ff:ff BGA=01:80:c2:00:00:00/ff:ff:ff:ff:ff:ff. broadcast multicast . --src . [!] -d, --destination [/] MAC . MAC -s ( ) . --dst . -c, --set-counter pcnt bcnt -A -I pcnt bcnt . -C -D pcnt bcnt . (MATCH EXTENSIONS) ebtables iptables -m . ebtables . 802_3 DSAP/SSAP 802.3 SNAP. LENGTH ( -p ). [!] --802_3-sap sap DSAP SSAP 802.3 . () . [!] --802_3-type type 802.3 DSAP SSAP 0xaa SNAP . () . 802.3 DSAP/SSAP 0xaa . among MAC MAC/IP MAC MAC/IP. : xx:xx:xx:xx:xx:xx[=ip.ip.ip.ip][,]. IP MAC . MAC/IP MAC IP ( ) . MAC ( "!" ). [!] --among-dst MAC . IPv4 ARP MAC/IP . [!] --among-src MAC . IPv4 ARP MAC/IP . [!] --among-dst-file --among-dst . [!] --among-src-file --among-src . arp (R)ARP. ARP RARP . [!] --arp-opcode opcode (R)ARP ( ebtables -h arp ). [!] --arp-htype hardware-type Ethernet ( type 1 ). (R)ARP Ethernet . [!] --arp-ptype protocol-type (r)arp ( IPv4 0x0800 ). (R)ARP IPv4 . [!] --arp-ip-src [/] IP (R)ARP. [!] --arp-ip-dst [/] IP (R)ARP. [!] --arp-mac-src [/] MAC (R)ARP. [!] --arp-mac-dst [/] MAC (R)ARP. [!] --arp-gratuitous ARP (ARP gratuitous): IPv4 IPv4 ARP . ip IPv4. IPv4 . [!] --ip-source [/] IP . --ip-src . [!] --ip-destination [/] IP . --ip-dst . [!] --ip-tos tos IP . IPv4. [!] --ip-protocol IP. --ip-proto . [!] --ip-source-port port1[:port2] IP 6 (TCP) 17 (UDP) 33 (DCCP) 132 (SCTP). --ip-protocol TCP UDP DCCP SCTP . port1 0:port2 port2 port1:65535 . --ip-sport . [!] --ip-destination-port port1[:port2] IP 6 (TCP) 17 (UDP) 33 (DCCP) 132 (SCTP). --ip-protocol TCP UDP DCCP SCTP . port1 0:port2 port2 port1:65535 . --ip-dport . ip6 IPv6. IPv6 . [!] --ip6-source [/] IPv6 . --ip6-src . [!] --ip6-destination [/] IPv6 . --ip6-dst . [!] --ip6-tclass tclass IPv6 . [!] --ip6-protocol IP. --ip6-proto . [!] --ip6-source-port port1[:port2] IPv6 6 (TCP) 17 (UDP) 33 (DCCP) 132 (SCTP). --ip6-protocol TCP UDP DCCP SCTP . port1 0:port2 port2 port1:65535 . --ip6-sport . [!] --ip6-destination-port port1[:port2] IPv6 6 (TCP) 17 (UDP) 33 (DCCP) 132 (SCTP). --ip6-protocol TCP UDP DCCP SCTP . port1 0:port2 port2 port1:65535 . --ip6-dport . [!] --ip6-icmp-type {type[:type]/code[:code]|typename} ipv6-icmp . type code . . type 0 255 . . : ebtables --help ip6 --ip6-protocol ipv6-icmp . limit (token bucket filter) . . --log . limit iptables . --limit [] : /second /minute /hour /day 3/hour . --limit-burst [] : 5 . mark_m [!] --mark [][/] (mark) . AND . . AND . . pkttype [!] --pkttype-type <<>> . : broadcast ( MAC ) multicast ( MAC ) host ( MAC ) otherhost ( ). stp STP BPDU (Bridge Protocol Data Unit). (-d) (BGA) . ( ) ( ) . [!] --stp-type BPDU ( 0 255) config BPDU (=0) tcn BPDU (=128) . [!] --stp-flags BPDU ( 0 255) topology-change (=1) topology-change-ack (=128) . [!] --stp-root-prio [prio][:prio] (0 65535). [!] --stp-root-addr [][/] MAC -s . [!] --stp-root-cost [cost][:cost] (0 4294967295). [!] --stp-sender-prio [prio][:prio] BPDU ( 0 65535). [!] --stp-sender-addr [][/] MAC BPDU -s . [!] --stp-port [port][:port] (0 65535). [!] --stp-msg-age [age][:age] (0 65535). [!] --stp-max-age [age][:age] (0 65535). [!] --stp-hello-time [time][:time] hello time ( 0 65535). [!] --stp-forward-delay [delay][:delay] (0 65535). vlan 802.1Q (TCI). 802_1Q (0x8100) . [!] --vlan-id id VLAN (VID). 0 4095. [!] --vlan-prio prio 0 7. VID 0 ("null VID") ( VID 0 ). [!] --vlan-encap type / . 0x0000 0xFFFF /etc/ethertypes . (WATCHER EXTENSIONS) . . log log syslog . --log : log-level= info log-prefix="" ip arp. --log-level . ebtables -h log . info . --log-prefix . --log-ip ip ip . ip . --log-ip6 ipv6 ipv6 . ipv6 . --log-arp (r)arp (r)arp . (r)arp . nflog nflog . nfnetlink_log netlink . . --nflog . --nflog-group nlgroup netlink ( 1 2^32-1) ( nfnetlink_log ). 1 . --nflog-prefix . --nflog-range ( nfnetlink_log ). nfnetlink_log . --nflog-threshold ( nfnetlink_log ). . 1 . ulog ulog (multicast) . log syslog . . ulog ( modprobe) : nlbufsiz . nlbufsiz=8192 . . nlgroup . 4096 . flushtimeout . 10 ( ) . --ulog : ulog-prefix="" ulog-nlgroup=1 ulog- cprange=4096 ulog-qthreshold=1. --ulog-prefix . --ulog-nlgroup ( 1 32). iptables ULOG ebtables ulog . 1 . --ulog-cprange . 0 nlbufsiz . 128*1024 128*1024 . --ulog-qthreshold . ulog ( flushtimeout ). (TARGET EXTENSIONS) arpreply arpreply PREROUTING nat . ARP ARP . MAC . ARP . ARP ARP ARP IP (CONTINUE). ARP (DROP). --arpreply-mac MAC : MAC MAC ARP . --arpreply-target . ARP ebtables ARP . DROP . dnat dnat PREROUTING OUTPUT nat . MAC . --to-destination MAC . --to-dst . --dnat-target . dnat ebtables . ACCEPT . CONTINUE . DROP BROUTING redirect . RETURN . RETURN ( ) . mark mark . bridge-nf / ebtables iptables . ebtables iptables . --mark-set . --mark-or OR . --mark-and AND . --mark-xor XOR . --mark-target . ebtables . ACCEPT . CONTINUE . redirect redirect MAC . PREROUTING nat . MAC . --redirect-target . MAC ebtables . ACCEPT . CONTINUE . DROP BROUTING . RETURN . RETURN . snat snat POSTROUTING nat . MAC . --to-source MAC . --to-src . --snat-target . snat ebtables . ACCEPT . CONTINUE . DROP . RETURN . RETURN . --snat-arp arp arp arp . (FILES) /etc/ethertypes (MAILINGLISTS) : http://netfilter.org/mailinglists.html (BUGS) ebtables string . (--atomic-file, --atomic-init, --atomic-save, --atomic-commit) nftables ebtables-save ebtables-restore . . (SEE ALSO) xtables-nft(8) iptables(8) ip(8) : https://wiki.nftables.org December 2011 EBTABLES(8)