Andrew Mercer
on this page

What it is

ebtables filters Ethernet frames crossing a Linux bridge: match on MAC addresses, VLAN tags, and Ethernet protocol, before IP is involved. It is the layer-2 sibling of iptables. Tables are filter (chains INPUT, FORWARD, OUTPUT), nat (PREROUTING, OUTPUT, POSTROUTING), and broute.

On current distributions ebtables is a shim over nftables' bridge family. Prefer writing table bridge rules directly in nftables for anything new.

Examples

sudo ebtables -L                                             # list rules

# Drop frames from one MAC address
sudo ebtables -A FORWARD -s 52:54:00:aa:bb:cc -j DROP

# Only allow IPv4 and ARP through the bridge
sudo ebtables -P FORWARD DROP
sudo ebtables -A FORWARD -p IPv4 -j ACCEPT
sudo ebtables -A FORWARD -p ARP -j ACCEPT

# Block a VLAN
sudo ebtables -A FORWARD -p 802_1Q --vlan-id 30 -j DROP

Making bridged traffic visible to iptables

By default bridged frames bypass iptables. The br_netfilter module (with net.bridge.bridge-nf-call-iptables=1) sends bridged IP traffic through the iptables FORWARD chain. This matters for container networking and Kubernetes nodes.

sudo modprobe br_netfilter
sudo sysctl -w net.bridge.bridge-nf-call-iptables=1