From: Ido Schimmel Date: Sun, 6 Nov 2022 11:39:57 +0000 (+0200) Subject: man: bridge: Reword description of "locked" bridge port option X-Git-Tag: v6.2.0~56 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=34c4cb13a0598c34b0ff47a28fdd4772080062fd;p=thirdparty%2Fiproute2.git man: bridge: Reword description of "locked" bridge port option Adjust the description to mention the "no_linklocal_learn" bridge option and make sure it is consistent between both the bridge(8) and ip-link(8) man pages. Signed-off-by: Ido Schimmel Signed-off-by: David Ahern --- diff --git a/man/man8/bridge.8 b/man/man8/bridge.8 index 1888f707b..e72826d75 100644 --- a/man/man8/bridge.8 +++ b/man/man8/bridge.8 @@ -574,12 +574,16 @@ flag is off. .TP .BR "locked on " or " locked off " -Controls whether a port will be locked, meaning that hosts behind the -port will not be able to communicate through the port unless an FDB -entry with the units MAC address is in the FDB. -The common use is that hosts are allowed access through authentication -with the IEEE 802.1X protocol or based on whitelists or like setups. -By default this flag is off. +Controls whether a port is locked or not. When locked, non-link-local frames +received through the port are dropped unless an FDB entry with the MAC source +address points to the port. The common use case is IEEE 802.1X where hosts can +authenticate themselves by exchanging EAPOL frames with an authenticator. After +authentication is complete, the user space control plane can install a matching +FDB entry to allow traffic from the host to be forwarded by the bridge. When +learning is enabled on a locked port, the +.B no_linklocal_learn +bridge option needs to be on to prevent the bridge from learning from received +EAPOL frames. By default this flag is off. .TP .BR "mab on " or " mab off " diff --git a/man/man8/ip-link.8.in b/man/man8/ip-link.8.in index 314c07d0f..235c839a4 100644 --- a/man/man8/ip-link.8.in +++ b/man/man8/ip-link.8.in @@ -2576,9 +2576,16 @@ is enabled on the port. By default this flag is off. default this flag is off. .BR locked " { " on " | " off " }" -- sets or unsets a port in locked mode, so that when enabled, hosts -behind the port cannot communicate through the port unless a FDB entry -representing the host is in the FDB. By default this flag is off. +- controls whether a port is locked or not. When locked, non-link-local frames +received through the port are dropped unless an FDB entry with the MAC source +address points to the port. The common use case is IEEE 802.1X where hosts can +authenticate themselves by exchanging EAPOL frames with an authenticator. After +authentication is complete, the user space control plane can install a matching +FDB entry to allow traffic from the host to be forwarded by the bridge. When +learning is enabled on a locked port, the +.B no_linklocal_learn +bridge option needs to be on to prevent the bridge from learning from received +EAPOL frames. By default this flag is off. .BR mab " { " on " | " off " }" - controls whether MAC Authentication Bypass (MAB) is enabled on the port or