> >>Thanks, interesting read. So we should disable learning/flooding on tap > >>devices? > > I think this could replace "mac filtering" from pve-firewall. (better than > iptables, and no need to implement ebtables?) > > I haved tested it, seem to works fine. great!