Vyos cannot (currently) do firewalling between the components of a bridge group. Eth0 and eth1 are in the same bridge group, so all that traffic is never seen by the firewall code. Bridge firewalling is controlled by ebtables (like iptables controls normal firewalls), which is not yet included in Vyos.
You can firewall traffic between br0 and eth3 however.
I don’t understand. What would firewalling traffic between br0 and eth3 do? I realistically will not have eth3 even hooked up once I get it in place. I just have eth3 as a maintenance line.
So unless I run the vyos as a router it cannot do ip blocking?
Micro, what is an IFB and how would I use it?
I am trying to just add an IP blocking solution to the network that has a lot setup in the modem, and I don’t want to have to set everything up all over again and take the network down. Any suggestions? Is there a different router that would allow me to add an IP block list? I really would like to use Vyos or Vyatta to accomplish this in bridge mode and not through router mode.