diff options
author | Jaehee Park <jhpark1013@gmail.com> | 2022-07-14 01:40:47 +0200 |
---|---|---|
committer | Jakub Kicinski <kuba@kernel.org> | 2022-07-16 03:55:49 +0200 |
commit | e68c5dcf0aacc48a23cedcb3ce81b8c60837f48c (patch) | |
tree | c89fddb75cef6e3d2e2159417e6e4ab9492a03ca /Documentation/networking/ip-sysctl.rst | |
parent | octeontx2-af: Set NIX link credits based on max LMAC (diff) | |
download | linux-e68c5dcf0aacc48a23cedcb3ce81b8c60837f48c.tar.xz linux-e68c5dcf0aacc48a23cedcb3ce81b8c60837f48c.zip |
net: ipv4: new arp_accept option to accept garp only if in-network
In many deployments, we want the option to not learn a neighbor from
garp if the src ip is not in the same subnet as an address configured
on the interface that received the garp message. net.ipv4.arp_accept
sysctl is currently used to control creation of a neigh from a
received garp packet. This patch adds a new option '2' to
net.ipv4.arp_accept which extends option '1' by including the subnet
check.
Signed-off-by: Jaehee Park <jhpark1013@gmail.com>
Suggested-by: Roopa Prabhu <roopa@nvidia.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'Documentation/networking/ip-sysctl.rst')
-rw-r--r-- | Documentation/networking/ip-sysctl.rst | 9 |
1 files changed, 6 insertions, 3 deletions
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst index 2b329042b38c..b31601405c54 100644 --- a/Documentation/networking/ip-sysctl.rst +++ b/Documentation/networking/ip-sysctl.rst @@ -1633,12 +1633,15 @@ arp_notify - BOOLEAN or hardware address changes. == ========================================================== -arp_accept - BOOLEAN - Define behavior for gratuitous ARP frames who's IP is not - already present in the ARP table: +arp_accept - INTEGER + Define behavior for accepting gratuitous ARP (garp) frames from devices + that are not already present in the ARP table: - 0 - don't create new entries in the ARP table - 1 - create new entries in the ARP table + - 2 - create new entries only if the source IP address is in the same + subnet as an address configured on the interface that received the + garp message. Both replies and requests type gratuitous arp will trigger the ARP table to be updated, if this setting is on. |