[PATCH v2] batman-adv: Introduce no noflood mark
linus.luessing at c0d3.blue
Tue May 7 17:34:59 CEST 2019
On Tue, May 07, 2019 at 05:17:23PM +0200, Linus Lüssing wrote:
> > This would even allow some fancy stuff like rate limiting or per hardif
> > behavior. With the problem that there is no package yet which does this in
> > gluon.
> Ah, that's an interesting idea. So basically filtering on the
> hardif instead of in batman-adv via some custom compiled BPF
> filters. So basically similar to writing a small program like the
> gluon-radv-filterd with a BPF_* parser?
And usability is of course different. Compared to writing a BPF
program it would just be an extra line in the firewall like here:
And setting the noflood_mark in batman-adv:
Also, we would not only need to package it for Gluon then but also
various Linux distributions used on gateways, I guess. To further
reduce the ARP broadcasts for vanished clients on gateways, for instance
(the second use-case).
Btw., I think rate-limiting would already be possible. We could
set the mark in a rate-limited fashion incoming on bat0 with
ebtables for instance.
Which could be useful to simplify gluon-ebtables-arp-limiter  a
bit. Currently there's a loop over the "batctl dat_cache" table
to add an exception to rate-limiting for addresses available in
More information about the B.A.T.M.A.N