Index | Thread | Search

From:
Janne Johansson <icepic.dz@gmail.com>
Subject:
Re: veb(4): "lock" mac addresses on ports
To:
Theo de Raadt <deraadt@openbsd.org>
Cc:
David Gwynne <david@gwynne.id.au>, tech@openbsd.org
Date:
Fri, 17 Oct 2025 07:57:55 +0200

Download raw body.

Thread
> > > there's similar functionality in vmware vswitches (and probably other
> > > hypervisors too) when you configure MAC address changes and forged
> > > transmits to be rejected.
> >
> > This might warrant a note somewhere that it "breaks" carp, since those
> > packets/interfaces will have a different mac. Or that you need to add
> > the carp mac(s) to this list, whichever is more convenient.
>
> I think people using carp can figure that out themselves, because it is
> first principles.

Sure, just something I ran into on VMWare long ago, just because of
that functionality of preventing the wrong mac on outgoing frames.

-- 
May the most significant bit of your life be positive.