Is there any way to... (firewall and bridge question)

Hi,

Is there any possible way to determine within a firewall chain the physical interface a packet entered IF that physical interface belongs to a bridge?

So far as I can tell by experimentation, this is impossible. The “in-interface” only matches the bridge interface.

Any ideas? Pointers?

Thanks!

look at ‘in-bridge-port’ and ‘out-bridge-port’

if not - check that /interface bridge settings set use-ip-firewall=yes

Those options for some reason doesn’t work, can someone address this problem?

what version of ROS do you use?