Cathy Zhou wrote:
I see. I am not sure about how priviledges works in this case. I would
think the user will not be given certain authorities to snoop certain
interfaces based on the interface names, but based on the characteristic
of the interfaces (for example, VLAN interfaces, interfaces of certain
zones etc.).
Yes.
But my point is that vanity naming provides the tool by which we can
replace ce1003 with bge5 transparently to those higher layers.
Thus the fact that bge5 has different behavior with respect to snoop
*might* be an issue.
But as I said before, I'm not convinced the issue is critical especially
since I don't know a low-complexity solution by which we can make a
distinction between snooping on the *mac* called bge5 (which shows
everything on the wire - all VLAN tags) and the link (at least I think
this corresponds to the link) called bge5, which is the abstraction that
only shows untagged frames.
So once I've used dladm to discover that link name "net1" has a device
name of bge17, can I use the existing techniques to map "bge17" to a
physical path name? E.g., today I can use
ls -l /dev/bge17
to find the physical path name in /devices/
Still, it depends on whether what style of nodes bge driver creates, if
it creates style-1 nodes, yes. Otherwise, it is the same as today.
OK
Erik
_______________________________________________
networking-discuss mailing list
[email protected]