Av. Reina Mercedes s/n, 41012 (Seville)
The current Linux bridge/ebtables architecture has several shortcomings. In the past those were worked around by adding 'header stripping' features to the bridge netfilter core or by invoking ip(6)tables hooks directly from the bridge layer.
Nftables, a framework to replace and unify the various packet filtering tools in the Linux kernel offers an opportunity to provide a more flexible approach to handling bridge filtering needs.
After a brief summary of the ebtables and bridge filtering issues, this will show some of the advantages that nft bridge offers over ebtables and present some features that are currently being worked on. Two of these will be presented in detail: