Thread (8 messages) flat view 8 messages, 2 authors, 2015-01-14

Re: [PATCH 0/5 net-next v4] VXLAN Group Policy Extension

From: David Miller <davem@davemloft.net>
Date: 2015-01-14 20:37:48

From: Thomas Graf <tgraf@suug.ch>
Date: Tue, 13 Jan 2015 17:20:41 +0100
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.

The extension is disabled by default and should be run on a distinct
port in mixed Linux VXLAN VTEP environments. Liberal VXLAN VTEPs
which ignore unknown reserved bits will be able to receive VXLAN-GBP
frames.
Thomas, unfortunately Tom's vxlan RCO patches were ready before your's
in my queue so I applied his work first.  You'll have to therefore
respin this series on top of it.

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help