-
Notifications
You must be signed in to change notification settings - Fork 247
Open
Labels
Milestone
Description
Gatekeeper currently supports some Linux applications and services through the KNI:
- ARP and ND, since Gatekeeper intercepts ARP/ND requests from the KNI and replies using the Gatekeeper L2 resolution cache
- ICMP Ping (IPv4 and IPv6), since Gatekeeper passes ping replies to the KNI
- BGP, since Gatekeeper passes BGP packets to the KNI
To support other tools and applications, we can add an option to the CPS block that allows the user to specify TCP and UDP ports. Packets that arrive to Gatekeeper on these ports should be passed to the KNI so that Linux applications can receive them. These ports should also have ntuple filters or ACL filters configured for them so that they can be steered to the CPS block.
This is basically a generalization of the way that BGP packets are handled.