Design for changing vm-switch from L2 (MAC-based) to L3 (IP-based) forwarding. Key changes: - Forward packets based on destination IP instead of MAC - ARP proxy responds with real peer MACs - ACL via peers/ directory (structural enforcement) - Anti-spoofing via source IP validation on ingress - Broadcast limited to 255.255.255.255 Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| config.nix | ||
| default.nix | ||
| options.nix | ||