{
    "mode": "man",
    "parameter": "ebtables-nft",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/ebtables-nft/8/json",
    "generated": "2026-10-04T12:33:26Z",
    "synopsis": "ebtables [-t table ] -[ACDI] chain rule specification [match extensions] [watcher extensions]\ntarget\nebtables [-t table ] -P chain ACCEPT | DROP | RETURN\nebtables [-t table ] -F [chain]\nebtables [-t table ] -Z [chain]\nebtables [-t table ] -L [-Z] [chain] [ [--Ln] | [--Lx] ] [--Lc] [--Lmac2]\nebtables [-t table ] -N chain [-P ACCEPT | DROP | RETURN]\nebtables [-t table ] -X [chain]\nebtables [-t table ] -E old-chain-name new-chain-name\nebtables [-t table ] --init-table",
    "sections": {
        "NAME": {
            "content": "ebtables - Ethernet bridge frame table administration (nft-based)\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "ebtables [-t table ] -[ACDI] chain rule specification [match extensions] [watcher extensions]\ntarget\nebtables [-t table ] -P chain ACCEPT | DROP | RETURN\nebtables [-t table ] -F [chain]\nebtables [-t table ] -Z [chain]\nebtables [-t table ] -L [-Z] [chain] [ [--Ln] | [--Lx] ] [--Lc] [--Lmac2]\nebtables [-t table ] -N chain [-P ACCEPT | DROP | RETURN]\nebtables [-t table ] -X [chain]\nebtables [-t table ] -E old-chain-name new-chain-name\nebtables [-t table ] --init-table\n\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "ebtables  is  an  application program used to set up and maintain the tables of rules (inside\nthe Linux kernel) that inspect Ethernet frames.  It is analogous to the iptables application,\nbut less complicated, due to the fact that the Ethernet protocol is much simpler than the  IP\nprotocol.\n\nCHAINS\nThere  are  three  ebtables tables with built-in chains in the Linux kernel. These tables are\nused to divide functionality into different sets of rules. Each set  of  rules  is  called  a\nchain.   Each  chain  is  an  ordered list of rules that can match Ethernet frames. If a rule\nmatches an Ethernet frame, then a processing specification tells what to do with that  match‐\ning  frame. The processing specification is called a 'target'. However, if the frame does not\nmatch the current rule in the chain, then the next rule in  the  chain  is  examined  and  so\nforth.   The  user can create new (user-defined) chains that can be used as the 'target' of a\nrule. User-defined chains are very useful to get better performance over the linear traversal\nof the rules and are also essential for structuring the filtering rules  into  well-organized\nand maintainable sets of rules.\n\nTARGETS\nA firewall rule specifies criteria for an Ethernet frame and a frame processing specification\ncalled  a  target.  When a frame matches a rule, then the next action performed by the kernel\nis specified by the target.  The target can be one of these values: ACCEPT,  DROP,  CONTINUE,\nRETURN, an 'extension' (see below) or a jump to a user-defined chain.\n\nACCEPT means to let the frame through.  DROP means the frame has to be dropped. In the BROUT‐\nING  chain however, the ACCEPT and DROP target have different meanings (see the info provided\nfor the -t option).  CONTINUE means the next rule has to be checked. This can be handy, f.e.,\nto know how many frames pass a certain point in the chain, to log those frames  or  to  apply\nmultiple  targets on a frame.  RETURN means stop traversing this chain and resume at the next\nrule in the previous (calling) chain.  For the extension targets please refer to  the  TARGET\nEXTENSIONS section of this man page.\n\nTABLES\nAs  stated  earlier, the table names are filter, nat and broute.  Of these tables, the filter\ntable is the default table that the command operates on.  If you are  working  with  a  table\nother  than filter, you will need to provide the -t argument.  Moreover, the -t argument must\nbe the first argument on the ebtables command line, if used.\n",
            "subsections": [
                {
                    "name": "-t, --table",
                    "content": "filter is the default table and contains three built-in chains: INPUT (for frames des‐\ntined for the bridge itself, on the level of the MAC destination address), OUTPUT (for\nlocally-generated or (b)routed frames) and FORWARD (for frames being forwarded by  the\nbridge).\nnat  is  mostly  used  to change the mac addresses and contains three built-in chains:\nPREROUTING (for altering frames as soon as they come in), OUTPUT (for altering locally\ngenerated or (b)routed frames before they are bridged) and POSTROUTING  (for  altering\nframes  as  they are about to go out). A small note on the naming of chains PREROUTING\nand POSTROUTING: it would be more accurate to call them PREFORWARDING and POSTFORWARD‐\nING, but for all those who come from the iptables world to ebtables it  is  easier  to\nhave  the same names. Note that you can change the name (-E) if you don't like the de‐\nfault.\nbroute is used to make a brouter, it has one built-in chain:  BROUTING.   The  targets\nDROP  and  ACCEPT have a special meaning in the broute table (these names are used for\ncompatibility reasons with ebtables-legacy).  DROP actually means the frame has to  be\nrouted,  while  ACCEPT  means  the frame has to be bridged. The BROUTING chain is tra‐\nversed very early.  Normally those frames would be bridged, but you can decide  other‐\nwise here.\n",
                    "flag": "-t",
                    "long": "--table"
                }
            ]
        },
        "EBTABLES COMMAND LINE ARGUMENTS": {
            "content": "After  the  initial ebtables '-t table' command line argument, the remaining arguments can be\ndivided into several groups.  These groups are commands, miscellaneous commands, rule  speci‐\nfications, match extensions, watcher extensions and target extensions.\n\nCOMMANDS\nThe  ebtables  command arguments specify the actions to perform on the table defined with the\n-t argument.  If you do not use the -t argument to name a table, the commands  apply  to  the\ndefault  filter  table.   Only  one command may be used on the command line at a time, except\nwhen the commands -L and -Z are combined or the commands -N and -P are combined.\n",
            "subsections": [
                {
                    "name": "-A, --append",
                    "content": "Append a rule to the end of the selected chain.\n",
                    "flag": "-A",
                    "long": "--append"
                },
                {
                    "name": "-D, --delete",
                    "content": "Delete the specified rule or rules from the selected chain. There are two ways to  use\nthis  command.  The  first is by specifying an interval of rule numbers to delete (di‐\nrectly after -D).  Syntax: startnr[:endnr] (use -L --Ln to list the rules with their\nrule number). When endnr is omitted, all rules starting from  startnr  are  deleted.\nUsing  negative numbers is allowed, for more details about using negative numbers, see\nthe -I command. The second usage is by specifying the complete rule as it  would  have\nbeen  specified when it was added. Only the first encountered rule that is the same as\nthis specified rule, in other words the matching rule with the lowest (positive)  rule\nnumber, is deleted.\n",
                    "flag": "-D",
                    "long": "--delete"
                },
                {
                    "name": "-C, --change-counters",
                    "content": "Change  the counters of the specified rule or rules from the selected chain. There are\ntwo ways to use this command. The first is by specifying an interval of  rule  numbers\nto  do  the changes on (directly after -C).  Syntax: startnr[:endnr] (use -L --Ln to\nlist the rules with their rule number). The details are the same as for  the  -D  com‐\nmand. The second usage is by specifying the complete rule as it would have been speci‐\nfied  when  it  was added. Only the counters of the first encountered rule that is the\nsame as this specified rule, in other words the matching rule with the  lowest  (posi‐\ntive)  rule  number,  are changed.  In the first usage, the counters are specified di‐\nrectly after the interval specification, in the second usage directly after -C.  First\nthe packet counter is specified, then the byte  counter.  If  the  specified  counters\nstart  with a '+', the counter values are added to the respective current counter val‐\nues.  If the specified counters start with a '-', the  counter  values  are  decreased\nfrom  the  respective current counter values. No bounds checking is done. If the coun‐\nters don't start with '+' or '-', the current counters are changed  to  the  specified\ncounters.\n",
                    "flag": "-C",
                    "long": "--change-counters"
                },
                {
                    "name": "-I, --insert",
                    "content": "Insert the specified rule into the selected chain at the specified rule number. If the\nrule number is not specified, the rule is added at the head of the chain.  If the cur‐\nrent  number  of  rules equals N, then the specified number can be between -N and N+1.\nFor a positive number i, it holds that i and i-N-1 specify the same place in the chain\nwhere the rule should be inserted. The rule number 0 specifies the place past the last\nrule in the chain and using this number is therefore equivalent to using the  -A  com‐\nmand.   Rule  numbers  structly  smaller  than 0 can be useful when more than one rule\nneeds to be inserted in a chain.\n",
                    "flag": "-I",
                    "long": "--insert"
                },
                {
                    "name": "-P, --policy",
                    "content": "Set the policy for the chain to the given target. The policy can be  ACCEPT,  DROP  or\nRETURN.\n",
                    "flag": "-P",
                    "long": "--policy"
                },
                {
                    "name": "-F, --flush",
                    "content": "Flush  the  selected chain. If no chain is selected, then every chain will be flushed.\nFlushing a chain does not change the policy of the chain, however.\n",
                    "flag": "-F",
                    "long": "--flush"
                },
                {
                    "name": "-Z, --zero",
                    "content": "Set the counters of the selected chain to zero. If no chain is selected, all the coun‐\nters are set to zero. The -Z command can be used in conjunction with the  -L  command.\nWhen  both the -Z and -L commands are used together in this way, the rule counters are\nprinted on the screen before they are set to zero.\n",
                    "flag": "-Z",
                    "long": "--zero"
                },
                {
                    "name": "-L, --list",
                    "content": "List all rules in the selected chain. If no chain is selected, all chains are listed.\nThe following options change the output of the -L command.\n--Ln\nPlaces the rule number in front of every rule. This option is  incompatible  with  the\n--Lx option.\n--Lc\nShows  the  counters at the end of each rule displayed by the -L command. Both a frame\ncounter (pcnt) and a byte counter (bcnt) are displayed.  The frame counter  shows  how\nmany  frames  have  matched  the  specific rule, the byte counter shows the sum of the\nframe sizes of these matching frames. Using this option in combination with  the  --Lx\noption causes the counters to be written out in the '-c <pcnt> <bcnt>' option format.\n--Lx\nChanges  the  output so that it produces a set of ebtables commands that construct the\ncontents of the chain, when specified.  If no chain is specified, ebtables commands to\nconstruct the contents of the table are given, including  commands  for  creating  the\nuser-defined chains (if any).  You can use this set of commands in an ebtables boot or\nreload  script.  For example the output could be used at system startup.  The --Lx op‐\ntion is incompatible with the --Ln listing option. Using the --Lx option together with\nthe --Lc option will cause the counters to be written out in the  '-c  <pcnt>  <bcnt>'\noption format.\n--Lmac2\nShows  all MAC addresses with the same length, adding leading zeroes if necessary. The\ndefault representation omits leading zeroes in the addresses.\n",
                    "flag": "-L",
                    "long": "--list"
                },
                {
                    "name": "-N, --new-chain",
                    "content": "Create a new user-defined chain with the given name. The number of user-defined chains\nis limited only by the number of possible chain names.  A user-defined chain name  has\na  maximum  length  of 31 characters. The standard policy of the user-defined chain is\nACCEPT. The policy of the new chain can be initialized to a different standard  target\nby  using  the  -P  command together with the -N command. In this case, the chain name\ndoes not have to be specified for the -P command.\n",
                    "flag": "-N",
                    "long": "--new-chain"
                },
                {
                    "name": "-X, --delete-chain",
                    "content": "Delete the specified user-defined chain. There must be no remaining references (jumps)\nto the specified chain, otherwise ebtables will refuse to delete it. If  no  chain  is\nspecified, all user-defined chains that aren't referenced will be removed.\n",
                    "flag": "-X",
                    "long": "--delete-chain"
                },
                {
                    "name": "-E, --rename-chain",
                    "content": "Rename  the specified chain to a new name.  Besides renaming a user-defined chain, you\ncan rename a standard chain to a name that suits your taste. For example, if you  like\nPREFORWARDING more than PREROUTING, then you can use the -E command to rename the PRE‐\nROUTING  chain.  If  you do rename one of the standard ebtables chain names, please be\nsure to mention this fact should you post a question on the  ebtables  mailing  lists.\nIt  would  be wise to use the standard name in your post. Renaming a standard ebtables\nchain in this fashion has no effect on the structure or functioning  of  the  ebtables\nkernel table.\n",
                    "flag": "-E",
                    "long": "--rename-chain"
                },
                {
                    "name": "--init-table",
                    "content": "Replace the current table data by the initial table data.\n\nMISCELLANEOUS COMMANDS",
                    "long": "--init-table"
                },
                {
                    "name": "-v, --verbose",
                    "content": "Verbose  mode.   For  appending,  insertion, deletion and replacement, this causes de‐\ntailed information on the rule or rules to be printed. -v may  be  specified  multiple\ntimes to possibly emit more detailed debug statements.\n",
                    "flag": "-v",
                    "long": "--verbose"
                },
                {
                    "name": "-V, --version",
                    "content": "Show the version of the ebtables userspace program.\n",
                    "flag": "-V",
                    "long": "--version"
                },
                {
                    "name": "-h, --help",
                    "content": "Give a brief description of the command syntax. Here you can also specify names of ex‐\ntensions and ebtables will try to write help about those extensions. E.g.  ebtables -h\nsnat  log  ip  arp.   Specify  listextensions to list all extensions supported by the\nuserspace utility.\n",
                    "flag": "-h",
                    "long": "--help"
                },
                {
                    "name": "-j, --jump _",
                    "content": "The target of the rule. This is one of the following values: ACCEPT,  DROP,  CONTINUE,\nRETURN, a target extension (see TARGET EXTENSIONS) or a user-defined chain name.\n",
                    "flag": "-j",
                    "long": "--jump"
                },
                {
                    "name": "-M, --modprobe _",
                    "content": "When talking to the kernel, use this program to try to automatically load missing ker‐\nnel modules.\n",
                    "flag": "-M",
                    "long": "--modprobe"
                },
                {
                    "name": "--concurrent",
                    "content": "Use a file lock to support concurrent scripts updating the ebtables kernel tables.\n\n\nRULE SPECIFICATIONS\nThe  following  command  line  arguments make up a rule specification (as used in the add and\ndelete commands). A \"!\" option before the specification inverts the test for that  specifica‐\ntion.  Apart  from these standard rule specifications there are some other command line argu‐\nments of interest.  See both the MATCH EXTENSIONS and the WATCHER EXTENSIONS below.\n",
                    "long": "--concurrent"
                },
                {
                    "name": "-p, --protocol",
                    "content": "The protocol that was responsible for creating the frame. This can  be  a  hexadecimal\nnumber, above 0x0600, a name (e.g.  ARP ) or LENGTH.  The protocol field of the Ether‐\nnet  frame can be used to denote the length of the header (802.2/802.3 networks). When\nthe value of that field is below or equals 0x0600, the value equals the  size  of  the\nheader  and shouldn't be used as a protocol number. Instead, all frames where the pro‐\ntocol field is used as the length field are assumed to be of the same 'protocol'.  The\nprotocol name used in ebtables for these frames is LENGTH.\nThe  file /etc/ethertypes can be used to show readable characters instead of hexadeci‐\nmal numbers for the protocols. For example, 0x0800 will be represented by  IPV4.   The\nuse  of this file is not case sensitive.  See that file for more information. The flag\n--proto is an alias for this option.\n",
                    "flag": "-p",
                    "long": "--protocol"
                },
                {
                    "name": "-i, --in-interface",
                    "content": "The interface (bridge port) via which a frame is received (this option  is  useful  in\nthe  INPUT,  FORWARD, PREROUTING and BROUTING chains). If the interface name ends with\n'+', then any interface name that begins with this name (disregarding '+') will match.\nThe flag --in-if is an alias for this option.\n\n--logical-in [!] name\nThe (logical) bridge interface via which a frame is received (this option is useful in\nthe INPUT, FORWARD, PREROUTING and BROUTING chains).  If the interface name ends  with\n'+', then any interface name that begins with this name (disregarding '+') will match.\n",
                    "flag": "-i",
                    "long": "--in-interface"
                },
                {
                    "name": "-o, --out-interface",
                    "content": "The interface (bridge port) via which a frame is going to be sent (this option is use‐\nful  in  the  OUTPUT, FORWARD and POSTROUTING chains). If the interface name ends with\n'+', then any interface name that begins with this name (disregarding '+') will match.\nThe flag --out-if is an alias for this option.\n\n--logical-out [!] name\nThe (logical) bridge interface via which a frame is going to be sent (this  option  is\nuseful  in  the  OUTPUT,  FORWARD and POSTROUTING chains).  If the interface name ends\nwith '+', then any interface name that begins with this name (disregarding  '+')  will\nmatch.\n",
                    "flag": "-o",
                    "long": "--out-interface"
                },
                {
                    "name": "-s, --source",
                    "content": "The  source  MAC  address.  Both mask and address are written as 6 hexadecimal numbers\nseparated by colons. Alternatively one can specify Unicast,  Multicast,  Broadcast  or\nBGA (Bridge Group Address):\nUnicast=00:00:00:00:00:00/01:00:00:00:00:00,                                    Multi‐\ncast=01:00:00:00:00:00/01:00:00:00:00:00,                                       Broad‐\ncast=ff:ff:ff:ff:ff:ff/ff:ff:ff:ff:ff:ff  or  BGA=01:80:c2:00:00:00/ff:ff:ff:ff:ff:ff.\nNote that a broadcast address will also match the multicast  specification.  The  flag\n--src is an alias for this option.\n",
                    "flag": "-s",
                    "long": "--source"
                },
                {
                    "name": "-d, --destination",
                    "content": "The  destination  MAC  address.  See -s (above) for more details on MAC addresses. The\nflag --dst is an alias for this option.\n",
                    "flag": "-d",
                    "long": "--destination"
                },
                {
                    "name": "-c, --set-counter _",
                    "content": "If used with -A or -I, then the packet and byte counters of the new rule will  be  set\nto pcnt, resp. bcnt.  If used with the -C or -D commands, only rules with a packet and\nbyte count equal to pcnt, resp. bcnt will match.\n\n\nMATCH EXTENSIONS\nEbtables  extensions  are  dynamically  loaded into the userspace tool, there is therefore no\nneed to explicitly load them with a -m option like is done  in  iptables.   These  extensions\ndeal with functionality supported by kernel modules supplemental to the core ebtables code.\n",
                    "flag": "-c",
                    "long": "--set-counter"
                },
                {
                    "name": "802_3",
                    "content": "Specify  802.3  DSAP/SSAP fields or SNAP type.  The protocol must be specified as LENGTH (see\nthe option  -p above).\n\n--8023-sap [!] sap\nDSAP and SSAP are two one byte 802.3 fields.  The bytes are always equal, so only  one\nbyte (hexadecimal) is needed as an argument.\n\n--8023-type [!] type\nIf  the 802.3 DSAP and SSAP values are 0xaa then the SNAP type field must be consulted\nto determine the payload protocol.  This is a two byte (hexadecimal)  argument.   Only\n802.3 frames with DSAP/SSAP 0xaa are checked for type.\n"
                },
                {
                    "name": "among",
                    "content": "Match  a MAC address or MAC/IP address pair versus a list of MAC addresses and MAC/IP address\npairs.  A list entry has the following format:  xx:xx:xx:xx:xx:xx[=ip.ip.ip.ip][,].  Multiple\nlist  entries are separated by a comma, specifying an IP address corresponding to the MAC ad‐\ndress is optional. Multiple MAC/IP address pairs with the same MAC address but  different  IP\naddress  (and  vice  versa) can be specified. If the MAC address doesn't match any entry from\nthe list, the frame doesn't match the rule (unless \"!\" was used).\n\n--among-dst [!] list\nCompare the MAC destination to the given list. If the Ethernet frame has type IPv4  or\nARP, then comparison with MAC/IP destination address pairs from the list is possible.\n\n--among-src [!] list\nCompare  the MAC source to the given list. If the Ethernet frame has type IPv4 or ARP,\nthen comparison with MAC/IP source address pairs from the list is possible.\n\n--among-dst-file [!] file\nSame as --among-dst but the list is read in from the specified file.\n\n--among-src-file [!] file\nSame as --among-src but the list is read in from the specified file.\n"
                },
                {
                    "name": "arp",
                    "content": "Specify (R)ARP fields. The protocol must be specified as ARP or RARP.\n\n--arp-opcode [!] opcode\nThe (R)ARP opcode (decimal or a string, for more details see ebtables -h arp).\n\n--arp-htype [!] hardware type\nThe hardware type, this can be a decimal or the string Ethernet (which  sets  type  to\n1). Most (R)ARP packets have Eternet as hardware type.\n\n--arp-ptype [!] protocol type\nThe protocol type for which the (r)arp is used (hexadecimal or the string IPv4, denot‐\ning 0x0800).  Most (R)ARP packets have protocol type IPv4.\n\n--arp-ip-src [!] address[/mask]\nThe (R)ARP IP source address specification.\n\n--arp-ip-dst [!] address[/mask]\nThe (R)ARP IP destination address specification.\n\n--arp-mac-src [!] address[/mask]\nThe (R)ARP MAC source address specification.\n\n--arp-mac-dst [!] address[/mask]\nThe (R)ARP MAC destination address specification.\n\n[!] --arp-gratuitous\nChecks  for  ARP  gratuitous  packets: checks equality of IPv4 source address and IPv4\ndestination address inside the ARP header.\n\nip\nSpecify IPv4 fields. The protocol must be specified as IPv4.\n\n--ip-source [!] address[/mask]\nThe source IP address.  The flag --ip-src is an alias for this option.\n\n--ip-destination [!] address[/mask]\nThe destination IP address.  The flag --ip-dst is an alias for this option.\n\n--ip-tos [!] tos\nThe IP type of service, in hexadecimal numbers.  IPv4.\n\n--ip-protocol [!] protocol\nThe IP protocol.  The flag --ip-proto is an alias for this option.\n\n--ip-source-port [!] port1[:port2]\nThe source port or port range for the IP protocols 6 (TCP), 17 (UDP), 33 (DCCP) or 132\n(SCTP). The --ip-protocol option must be specified as TCP,  UDP,  DCCP  or  SCTP.   If\nport1  is  omitted,  0:port2  is  used;  if port2 is omitted but a colon is specified,\nport1:65535 is used.  The flag --ip-sport is an alias for this option.\n\n--ip-destination-port [!] port1[:port2]\nThe destination port or port range for ip protocols 6 (TCP), 17 (UDP),  33  (DCCP)  or\n132  (SCTP). The --ip-protocol option must be specified as TCP, UDP, DCCP or SCTP.  If\nport1 is omitted, 0:port2 is used; if port2 is  omitted  but  a  colon  is  specified,\nport1:65535 is used.  The flag --ip-dport is an alias for this option.\n"
                },
                {
                    "name": "ip6",
                    "content": "Specify IPv6 fields. The protocol must be specified as IPv6.\n\n--ip6-source [!] address[/mask]\nThe source IPv6 address.  The flag --ip6-src is an alias for this option.\n\n--ip6-destination [!] address[/mask]\nThe destination IPv6 address.  The flag --ip6-dst is an alias for this option.\n\n--ip6-tclass [!] tclass\nThe IPv6 traffic class, in hexadecimal numbers.\n\n--ip6-protocol [!] protocol\nThe IP protocol.  The flag --ip6-proto is an alias for this option.\n\n--ip6-source-port [!] port1[:port2]\nThe  source  port or port range for the IPv6 protocols 6 (TCP), 17 (UDP), 33 (DCCP) or\n132 (SCTP). The --ip6-protocol option must be specified as TCP, UDP, DCCP or SCTP.  If\nport1 is omitted, 0:port2 is used; if port2 is  omitted  but  a  colon  is  specified,\nport1:65535 is used.  The flag --ip6-sport is an alias for this option.\n\n--ip6-destination-port [!] port1[:port2]\nThe  destination port or port range for IPv6 protocols 6 (TCP), 17 (UDP), 33 (DCCP) or\n132 (SCTP). The --ip6-protocol option must be specified as TCP, UDP, DCCP or SCTP.  If\nport1 is omitted, 0:port2 is used; if port2 is  omitted  but  a  colon  is  specified,\nport1:65535 is used.  The flag --ip6-dport is an alias for this option.\n\n--ip6-icmp-type [!] {type[:type]/code[:code]|typename}\nSpecify  ipv6-icmp  type  and  code  to match.  Ranges for both type and code are sup‐\nported. Type and code are separated by a slash. Valid numbers for type and range are 0\nto 255.  To match a single type including all valid codes, symbolic names can be  used\ninstead of numbers. The list of known type names is shown by the command\nebtables --help ip6\nThis option is only valid for --ip6-prococol ipv6-icmp.\n"
                },
                {
                    "name": "limit",
                    "content": "This  module matches at a limited rate using a token bucket filter.  A rule using this exten‐\nsion will match until this limit is reached.  It can be used with the --log watcher  to  give\nlimited logging, for example. Its use is the same as the limit match of iptables.\n\n--limit [value]\nMaximum  average  matching  rate:  specified  as  a  number, with an optional /second,\n/minute, /hour, or /day suffix; the default is 3/hour.\n\n--limit-burst [number]\nMaximum initial number of packets to match: this number gets recharged  by  one  every\ntime the limit specified above is not reached, up to this number; the default is 5.\n"
                },
                {
                    "name": "mark_m",
                    "content": "--mark [!] [value][/mask]\nMatches  frames with the given unsigned mark value. If a value and mask are specified,\nthe logical AND of the mark value of the frame and the user-specified  mask  is  taken\nbefore  comparing  it  with  the  user-specified mark value. When only a mark value is\nspecified, the packet only matches when the mark value of the frame equals  the  user-\nspecified  mark value.  If only a mask is specified, the logical AND of the mark value\nof the frame and the user-specified mask is taken and the frame matches when  the  re‐\nsult of this logical AND is non-zero. Only specifying a mask is useful to match multi‐\nple mark values.\n"
                },
                {
                    "name": "pkttype",
                    "content": "--pkttype-type [!] type\nMatches  on the Ethernet \"class\" of the frame, which is determined by the generic net‐\nworking code. Possible values: broadcast (MAC destination is the  broadcast  address),\nmulticast  (MAC  destination is a multicast address), host (MAC destination is the re‐\nceiving network device), or otherhost (none of the above).\n"
                },
                {
                    "name": "stp",
                    "content": "Specify stp BPDU (bridge protocol data unit) fields. The destination  address  (-d)  must  be\nspecified as the bridge group address (BGA).  For all options for which a range of values can\nbe  specified,  it  holds that if the lower bound is omitted (but the colon is not), then the\nlowest possible lower bound for that option is used, while if the upper bound is omitted (but\nthe colon again is not), the highest possible upper bound for that option is used.\n\n--stp-type [!] type\nThe BPDU type (0-255), recognized non-numerical types are config, denoting a  configu‐\nration BPDU (=0), and tcn, denothing a topology change notification BPDU (=128).\n\n--stp-flags [!] flag\nThe  BPDU  flag  (0-255), recognized non-numerical flags are topology-change, denoting\nthe topology change flag (=1), and topology-change-ack, denoting the  topology  change\nacknowledgement flag (=128).\n\n--stp-root-prio [!] [prio][:prio]\nThe root priority (0-65535) range.\n\n--stp-root-addr [!] [address][/mask]\nThe root mac address, see the option -s for more details.\n\n--stp-root-cost [!] [cost][:cost]\nThe root path cost (0-4294967295) range.\n\n--stp-sender-prio [!] [prio][:prio]\nThe BPDU's sender priority (0-65535) range.\n\n--stp-sender-addr [!] [address][/mask]\nThe BPDU's sender mac address, see the option -s for more details.\n\n--stp-port [!] [port][:port]\nThe port identifier (0-65535) range.\n\n--stp-msg-age [!] [age][:age]\nThe message age timer (0-65535) range.\n\n--stp-max-age [!] [age][:age]\nThe max age timer (0-65535) range.\n\n--stp-hello-time [!] [time][:time]\nThe hello time timer (0-65535) range.\n\n--stp-forward-delay [!] [delay][:delay]\nThe forward delay timer (0-65535) range.\n"
                },
                {
                    "name": "vlan",
                    "content": "Specify  802.1Q  Tag  Control  Information  fields.  The protocol must be specified as 8021Q\n(0x8100).\n\n--vlan-id [!] id\nThe VLAN identifier field (VID). Decimal number from 0 to 4095.\n\n--vlan-prio [!] prio\nThe user priority field, a decimal number from 0 to 7.  The VID should  be  set  to  0\n(\"null VID\") or unspecified (in the latter case the VID is deliberately set to 0).\n\n--vlan-encap [!] type\nThe  encapsulated  Ethernet frame type/length.  Specified as a hexadecimal number from\n0x0000 to 0xFFFF or as a symbolic name from /etc/ethertypes.\n\n\nWATCHER EXTENSIONS\nWatchers only look at frames passing by, they don't modify them  nor  decide  to  accept  the\nframes  or not. These watchers only see the frame if the frame matches the rule, and they see\nit before the target is executed.\n"
                },
                {
                    "name": "log",
                    "content": "The log watcher writes descriptive data about a frame to the syslog.\n"
                },
                {
                    "name": "--log",
                    "content": "Log with the default logging options: log-level= info, log-prefix=\"\", no  ip  logging,\nno arp logging.\n\n--log-level level\nDefines  the logging level. For the possible values, see ebtables -h log.  The default\nlevel is info.\n\n--log-prefix text\nDefines the prefix text to be printed at the beginning of the line  with  the  logging\ninformation.\n",
                    "long": "--log"
                },
                {
                    "name": "--log-ip",
                    "content": "Will log the ip information when a frame made by the ip protocol matches the rule. The\ndefault is no ip information logging.\n",
                    "long": "--log-ip"
                },
                {
                    "name": "--log-ip6",
                    "content": "Will log the ipv6 information when a frame made by the ipv6 protocol matches the rule.\nThe default is no ipv6 information logging.\n",
                    "long": "--log-ip6"
                },
                {
                    "name": "--log-arp",
                    "content": "Will  log the (r)arp information when a frame made by the (r)arp protocols matches the\nrule. The default is no (r)arp information logging.\n",
                    "long": "--log-arp"
                },
                {
                    "name": "nflog",
                    "content": "The nflog watcher passes the packet to the loaded logging backend in order to log the packet.\nThis is usually used in combination with nfnetlinklog as logging backend, which will  multi‐\ncast  the packet through a netlink socket to the specified multicast group. One or more user‐\nspace processes may subscribe to the group to receive the packets.\n"
                },
                {
                    "name": "--nflog",
                    "content": "Log with the default logging options\n\n--nflog-group nlgroup\nThe  netlink  group  (1  -  2^32-1)  to  which  packets  are  (only   applicable   for\nnfnetlinklog). The default value is 1.\n\n--nflog-prefix prefix\nA  prefix  string  to include in the log message, up to 30 characters long, useful for\ndistinguishing messages in the logs.\n\n--nflog-range size\nThe number of bytes to be copied to userspace  (only  applicable  for  nfnetlinklog).\nnfnetlinklog instances may specify their own range, this option overrides it.\n\n--nflog-threshold size\nNumber  of  packets  to queue inside the kernel before sending them to userspace (only\napplicable for nfnetlinklog). Higher values result in less overhead per  packet,  but\nincrease delay until the packets reach userspace. The default value is 1.\n",
                    "long": "--nflog"
                },
                {
                    "name": "ulog",
                    "content": "The  ulog  watcher  passes  the  packet to a userspace logging daemon using netlink multicast\nsockets. This differs from the log watcher in the sense that the complete packet is  sent  to\nuserspace  instead  of a descriptive text and that netlink multicast sockets are used instead\nof the syslog.  This watcher enables parsing of packets with userspace programs, the physical\nbridge in and out ports are also included in the netlink messages.  The ulog  watcher  module\naccepts 2 parameters when the module is loaded into the kernel (e.g. with modprobe): nlbufsiz\nspecifies  how  big the buffer for each netlink multicast group is. If you say nlbufsiz=8192,\nfor example, up to eight kB of packets will get accumulated in the kernel until they are sent\nto userspace. It is not possible to allocate more than 128kB. Please also keep in  mind  that\nthis  buffer size is allocated for each nlgroup you are using, so the total kernel memory us‐\nage increases by that factor. The default is 4096.  flushtimeout  specifies  after  how  many\nhundredths  of  a second the queue should be flushed, even if it is not full yet. The default\nis 10 (one tenth of a second).\n"
                },
                {
                    "name": "--ulog",
                    "content": "Use the default settings:  ulog-prefix=\"\",  ulog-nlgroup=1,  ulog-cprange=4096,  ulog-\nqthreshold=1.\n\n--ulog-prefix text\nDefines the prefix included with the packets sent to userspace.\n\n--ulog-nlgroup group\nDefines  which  netlink  group  number  to use (a number from 1 to 32).  Make sure the\nnetlink group numbers used for the iptables ULOG target differ from those used for the\nebtables ulog watcher.  The default group number is 1.\n\n--ulog-cprange range\nDefines the maximum copy range to userspace, for packets matching the  rule.  The  de‐\nfault  range is 0, which means the maximum copy range is given by nlbufsiz.  A maximum\ncopy range larger than 128*1024 is meaningless as the packets sent to  userspace  have\nan upper size limit of 128*1024.\n\n--ulog-qthreshold threshold\nQueue  at  most  threshold  number  of packets before sending them to userspace with a\nnetlink socket. Note that packets can be sent to userspace before the queue  is  full,\nthis  happens when the ulog kernel timer goes off (the frequency of this timer depends\non flushtimeout).\n\nTARGET EXTENSIONS",
                    "long": "--ulog"
                },
                {
                    "name": "arpreply",
                    "content": "The arpreply target can be used in the PREROUTING chain of the nat  table.   If  this  target\nsees  an  ARP request it will automatically reply with an ARP reply. The used MAC address for\nthe reply can be specified.  The protocol must be specified as ARP.  When the ARP message  is\nnot an ARP request or when the ARP request isn't for an IP address on an Ethernet network, it\nis  ignored  by  this  target  (CONTINUE).   When the ARP request is malformed, it is dropped\n(DROP).\n\n--arpreply-mac address\nSpecifies the MAC address to reply with: the Ethernet source MAC and the  ARP  payload\nsource MAC will be filled in with this address.\n\n--arpreply-target target\nSpecifies the standard target. After sending the ARP reply, the rule still has to give\na standard target so ebtables knows what to do with the ARP request.  The default tar‐\nget is DROP.\n"
                },
                {
                    "name": "dnat",
                    "content": "The  dnat  target  can only be used in the PREROUTING and OUTPUT chains of the nat table.  It\nspecifies that the destination MAC address has to be changed.\n\n--to-destination address\nChange the destination MAC address to the specified address.  The flag --to-dst is  an\nalias for this option.\n\n--dnat-target target\nSpecifies  the  standard  target.  After  doing the dnat, the rule still has to give a\nstandard target so ebtables knows what to do with the dnated frame.  The default  tar‐\nget is ACCEPT.  Making it CONTINUE could let you use multiple target extensions on the\nsame  frame. Making it DROP only makes sense in the BROUTING chain but using the redi‐\nrect target is more logical there. RETURN is also allowed. Note that using RETURN in a\nbase chain is not allowed (for obvious reasons).\n"
                },
                {
                    "name": "mark",
                    "content": "The mark target can be used in every chain of every table. It is possible to use the  marking\nof  a  frame/packet in both ebtables and iptables, if the bridge-nf code is compiled into the\nkernel. Both put the marking at the same place. This allows for a form of  communication  be‐\ntween ebtables and iptables.\n\n--mark-set value\nMark the frame with the specified non-negative value.\n\n--mark-or value\nOr the frame with the specified non-negative value.\n\n--mark-and value\nAnd the frame with the specified non-negative value.\n\n--mark-xor value\nXor the frame with the specified non-negative value.\n\n--mark-target target\nSpecifies  the  standard target. After marking the frame, the rule still has to give a\nstandard target so ebtables knows what to do.  The default target is ACCEPT. Making it\nCONTINUE can let you do other things with the frame in subsequent rules of the chain.\n"
                },
                {
                    "name": "redirect",
                    "content": "The redirect target will change the MAC target address to that of the bridge device the frame\narrived on. This target can only be used in the PREROUTING chain of the nat table.   The  MAC\naddress of the bridge is used as destination address.\"\n\n--redirect-target target\nSpecifies  the  standard  target.  After doing the MAC redirect, the rule still has to\ngive a standard target so ebtables knows what to do.  The default  target  is  ACCEPT.\nMaking  it  CONTINUE  could  let you use multiple target extensions on the same frame.\nMaking it DROP in the BROUTING chain will let the frames be routed. RETURN is also al‐\nlowed. Note that using RETURN in a base chain is not allowed.\n"
                },
                {
                    "name": "snat",
                    "content": "The snat target can only be used in the POSTROUTING chain of the  nat  table.   It  specifies\nthat the source MAC address has to be changed.\n\n--to-source address\nChanges the source MAC address to the specified address. The flag --to-src is an alias\nfor this option.\n\n--snat-target target\nSpecifies  the  standard  target.  After  doing the snat, the rule still has to give a\nstandard target so ebtables knows what to do.  The default target is ACCEPT. Making it\nCONTINUE could let you use multiple target extensions on the  same  frame.  Making  it\nDROP  doesn't make sense, but you could do that too. RETURN is also allowed. Note that\nusing RETURN in a base chain is not allowed.\n"
                },
                {
                    "name": "--snat-arp",
                    "content": "Also change the hardware source address inside the arp header if the packet is an  arp\nmessage and the hardware address length in the arp header is 6 bytes.\n",
                    "long": "--snat-arp"
                }
            ]
        },
        "FILES": {
            "content": "/etc/ethertypes\n",
            "subsections": []
        },
        "MAILINGLISTS": {
            "content": "See http://netfilter.org/mailinglists.html\n",
            "subsections": []
        },
        "BUGS": {
            "content": "The  version of ebtables this man page ships with does not support the string match. Further,\nsupport for atomic-options (--atomic-file, --atomic-init, --atomic-save, --atomic-commit) has\nnot been implemented, although ebtables-save and ebtables-restore might replace them entirely\ngiven the inherent atomicity of nftables.  Finally, this list is probably not complete.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "xtables-nft(8), iptables(8), ip(8)\n\nSee https://wiki.nftables.org\n\nDecember 2011                                EBTABLES(8)",
            "subsections": []
        }
    },
    "summary": "ebtables - Ethernet bridge frame table administration (nft-based)",
    "flags": [
        {
            "flag": "-t",
            "long": "--table",
            "arg": null,
            "description": "filter is the default table and contains three built-in chains: INPUT (for frames des‐ tined for the bridge itself, on the level of the MAC destination address), OUTPUT (for locally-generated or (b)routed frames) and FORWARD (for frames being forwarded by the bridge). nat is mostly used to change the mac addresses and contains three built-in chains: PREROUTING (for altering frames as soon as they come in), OUTPUT (for altering locally generated or (b)routed frames before they are bridged) and POSTROUTING (for altering frames as they are about to go out). A small note on the naming of chains PREROUTING and POSTROUTING: it would be more accurate to call them PREFORWARDING and POSTFORWARD‐ ING, but for all those who come from the iptables world to ebtables it is easier to have the same names. Note that you can change the name (-E) if you don't like the de‐ fault. broute is used to make a brouter, it has one built-in chain: BROUTING. The targets DROP and ACCEPT have a special meaning in the broute table (these names are used for compatibility reasons with ebtables-legacy). DROP actually means the frame has to be routed, while ACCEPT means the frame has to be bridged. The BROUTING chain is tra‐ versed very early. Normally those frames would be bridged, but you can decide other‐ wise here."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "xtables-nft",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/xtables-nft/8/json"
        },
        {
            "name": "iptables",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/iptables/8/json"
        },
        {
            "name": "ip",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ip/8/json"
        }
    ]
}