Linux VLAN-Aware Bridge: Enforce 802.1Q with iproute2 - 夜莺博客

Linux VLAN-Aware Bridge: Enforce 802.1Q with iproute2

A Linux bridge without VLAN filtering is not a switch — it is a hub with a port table. It will happily forward frames between ports that your design says belong to different VLANs, so any hypervisor or container host that treats its bridge as a security boundary is wrong until VLAN filtering is switched on. This guide builds a proper VLAN-aware bridge with iproute2, then verifies it with the same mental model you would use on a hardware switch.

Create the bridge with filtering enabled

ip link add name br0 type bridge vlan_filtering 1 vlan_default_pvid 1
ip link set br0 up
ip link set eth0 master br0
ip link set tap0 master br0

vlan_filtering 1 is the switch that turns membership into enforcement. vlan_default_pvid sets the VLAN assigned to untagged ingress; setting it to 0 means no default PVID and no VLANs configured on ports by default, which is a stricter starting point for a fabric that will be fully specified.

Trunk port: tagged VLANs

bridge vlan add dev eth0 vid 10
bridge vlan add dev eth0 vid 20
bridge vlan add dev eth0 vid 20 pvid untagged   # if VLAN 20 is the untagged one

Access port: pvid and untagged egress

bridge vlan add dev tap0 vid 10 pvid untagged
bridge vlan add dev tap1 vid 20 pvid untagged

A classic access port is exactly pvid untagged: untagged frames entering the port are classified into that VLAN, and frames leaving the port for that VLAN are sent untagged. The connected VM or container never sees a tag.

The bridge master is a port too

bridge vlan add dev br0 vid 10 self
bridge vlan add dev br0 vid 20 self

Forgetting the self entries is the classic silent failure: ports can carry VLANs, but the bridge itself drops them, so any host interface stacked on the bridge sees nothing. A VLAN must be configured both on the bridge master and on each enslaved port that should carry it.

Host IP addresses belong on stacked VLAN interfaces

ip link add link br0 name br0.10 type vlan id 10
ip addr add 10.10.10.1/24 dev br0.10
ip link set br0.10 up

Give member NICs no IP address at all. Address the bridge only for an untagged management VLAN, and use br0.X interfaces for routed VLANs — the equivalent of an SVI. Cross-VLAN forwarding from the host then requires IP forwarding and an explicit firewall policy; VLAN filtering alone is isolation, not routing.

Verification

bridge vlan show
bridge link show
ip -d link show br0 | grep vlan_filtering
bridge fdb show

bridge vlan show prints the per-port VLAN table with PVID and Egress Untagged flags — the same information a switch's show vlan port gives you. Compare it against what the design says, then test actual isolation by pinging across VLANs and confirming it fails without an explicit routing rule.

Related reading: Cumulus Linux VLAN-aware bridge configuration, Linux network namespaces and veth, VLAN hopping and double tagging prevention.

原文链接:https://docs.bisdn.de/network_configuration/vlan_bridging.html