Project

General

Profile

Actions

New Content #14317

closed

Add docs for Ethernet Filtering (Plus Only)

Added by Jim Pingle about 2 years ago. Updated over 1 year ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Firewall Rules
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:

Description

Ethernet/L2 filtering was added to Plus in #14308 and needs documentation.

A few notable items:

  • Plus only feature
  • Off by default, enabled via checkbox option on System > Advanced, Firewall & NAT tab
  • Rules are managed on a single dedicated tab at Firewall > Rules, Ethernet tab that only appears when the option is enabled
  • Only effective on interfaces that support L2 (e.g. they have a MAC address and operate at L2 with ARP and so on), would have no effect on interfaces that do not carry L2 info in packets.
  • Passes by default
  • Does not keep state, so recommend adding rules in pairs (one for each of in/out direction)
  • Plugin hook is available for packages to add Ethernet rules.

Related issues

Related to New Content #14375: Add recipe for AT&T fiber ONT/Modem auth bridge setupResolvedJim Pingle

Actions
Actions #1

Updated by Jim Pingle about 2 years ago

  • Status changed from New to In Progress
Actions #2

Updated by Jim Pingle about 2 years ago

  • % Done changed from 0 to 30

I started on them here:

https://gitlab.netgate.com/docs/pfSense-docs/-/commit/8c98f9424906a84009ddd9b0640c633d0ca6a270

Will likely get sidetracked a bit because the Advanced options docs are a bit out of date so adding the checkbox option there will require revising a bunch of that content first.

Actions #3

Updated by Jim Pingle about 2 years ago

  • % Done changed from 30 to 40

Reorganized Advanced options and added the Ethernet Rules option along the way: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/3d9e7aeeb46b67caea031521900e3cb046bf02df

Actions #6

Updated by Jim Pingle about 2 years ago

I also added a recipe to configure an AT&T style WAN using Ethernet rules and other recent features:

https://gitlab.netgate.com/docs/pfSense-docs/-/commit/9b00b71603f0bd119f8b9db26a4a53e8f208b723

I'm splitting that off into its own separate Redmine issue: #14375

Actions #7

Updated by Jim Pingle about 2 years ago

  • Related to New Content #14375: Add recipe for AT&T fiber ONT/Modem auth bridge setup added
Actions #8

Updated by Jim Pingle over 1 year ago

  • Status changed from Feedback to Resolved
Actions

Also available in: Atom PDF