Re: [ovs-discuss] arp spoofing

2012-05-21 Thread Sergio Kviato
On May 21, 2012, at 5:11 AM, faicker mo wrote: > > On 2012-5-20, at 上午12:27, Sergio Kviato wrote: > >> >> >> Sent from my iPhone >> >> On May 19, 2012, at 19:02, faicker mo wrote: >> >>> >>> On 2012-5-19, at 下午11:11, Ben Pfaff wrote: >>> On Sat, May 19, 2012 at 09:30:40PM +0800, fai

Re: [ovs-discuss] arp spoofing

2012-05-20 Thread faicker mo
On 2012-5-20, at 上午12:27, Sergio Kviato wrote: > > > Sent from my iPhone > > On May 19, 2012, at 19:02, faicker mo wrote: > >> >> On 2012-5-19, at 下午11:11, Ben Pfaff wrote: >> >>> On Sat, May 19, 2012 at 09:30:40PM +0800, faicker mo wrote: I have viewed the ovs-ofctl man page, I found

Re: [ovs-discuss] arp spoofing

2012-05-19 Thread Sergio Kviato
Sent from my iPhone On May 19, 2012, at 19:02, faicker mo wrote: > > On 2012-5-19, at 下午11:11, Ben Pfaff wrote: > >> On Sat, May 19, 2012 at 09:30:40PM +0800, faicker mo wrote: >>> I have viewed the ovs-ofctl man page, I found that the arp match has >>> only arp_sha and arp_dha. It can't mat

Re: [ovs-discuss] arp spoofing

2012-05-19 Thread faicker mo
On 2012-5-19, at 下午11:11, Ben Pfaff wrote: > On Sat, May 19, 2012 at 09:30:40PM +0800, faicker mo wrote: >> I have viewed the ovs-ofctl man page, I found that the arp match has >> only arp_sha and arp_dha. It can't match the source ip in arp(SPA) and >> destination ip(DPA) in arp. Without this, t

Re: [ovs-discuss] arp spoofing

2012-05-19 Thread Ben Pfaff
On Sat, May 19, 2012 at 09:30:40PM +0800, faicker mo wrote: > I have viewed the ovs-ofctl man page, I found that the arp match has > only arp_sha and arp_dha. It can't match the source ip in arp(SPA) and > destination ip(DPA) in arp. Without this, the arp spoofing can't be > prevented. Use nw_src

[ovs-discuss] arp spoofing

2012-05-19 Thread faicker mo
I have viewed the ovs-ofctl man page, I found that the arp match has only arp_sha and arp_dha. It can't match the source ip in arp(SPA) and destination ip(DPA) in arp. Without this, the arp spoofing can't be prevented. OVS replaces the bridge default in kernel. Ebtables can't work. But no