Legacy - multi interfaces on same network create antispoof problem
Status: Beta
Brought to you by:
jsulliva
If we create multiple interfaces on the same network and anti-spoof is enabled, we cut off traffic because of conflicting antispoofing rules in the mangle table PREROUTING chain, e.g., one that says if !eth1 and source 172.16.20.0/24 DROP and another that says !eth2 and source 172.16.20.0/24 DROP. We'll need to detect if multiple interfaces are operating on the same network and automatically disable anti-spoof.