I have br-lan interface with members eth0 and eth1.
I am trying to filter and forward some specific traffics from bridge to another interfaces like tun or tap
eth0 is WAN
eth1 is LAN
i wan to block icmp request coming from LAN to WAN on eth1
and there is a problem like below . Any help would be appreciated.
root@alfa:~# iptables -A FORWARD -m physdev --physdev-in eth1 --physdev-out eth0 -p icmp -j REJECT
[ 2752.462243] xt_physdev: using --physdev-out and --physdev-is-out are only supported in the FORWARD and POSTROUTING chains with bridged traffic.
[ 2752.475265] xt_physdev: using --physdev-out and --physdev-is-out are only supported in the FORWARD and POSTROUTING chains with bridged traffic.
root@alfa:~#
sorry for late reply but actually it worked for me although this warn . So now i cannot ping from eth0 to eth1 and eth1 to eth0 . [ 2752.462243] xt_physdev: using --physdev-out and --physdev-is-out are only supported in the FORWARD and POSTROUTING chains with bridged traffic.