HomeFreeBSD

bridge: Make 802.1ad (Q-in-Q) configurable

Description

bridge: Make 802.1ad (Q-in-Q) configurable

Allowing tag stacking by default can permit VLAN-hopping attacks in
certain configurations. To mitigate this, disallow sending Q-in-Q
frames by default unless the new "qinq" option is enabled on the
interface. The bridge flag "defqinq" can be used to restore the
previous behaviour of allowing Q-in-Q on all interfaces.

The bridge.4 changes from the differential are omitted here and
will be landed via D51185.

Reviewed by: kevans, pauamma_gundo.com (manpages)
Differential Revision: https://reviews.freebsd.org/D51227

Details

Provenance
ivyAuthored on Aug 5 2025, 5:43 PM
Reviewer
kevans
Differential Revision
D51227: bridge: make 802.1ad (Q-in-Q) configurable
Parents
rGd1bcdbd2470f: libutil++: Add package definition
Branches
Unknown
Tags
Unknown