4 ms·
The "connecting two ethernet MACs [with] filtering" seems like an interesting project. I guess a "simple" (and possibly useless) idea could be to do filtering b
by trapperkeeper79 10y ago
The "connecting two ethernet MACs [with] filtering" seems like an interesting project. I guess a "simple" (and possibly useless) idea could be to do filtering based on MAC addresses in the enthernet frame. Is there open IP for this? I guess I'm asking how a hobbyist gets into this :-) If anyone knows of an existing project, I'd appreciate a pointer.
- pjc50 10y agoOpenCores is one possible source of examples. You could start by modifying e.g. http://opencores.org/project,mac_layer_switch http://opencores.org/project,mac_layer_switch
- musicnarcoman 10y agoIt is definitely possible, me and a few other students did it in a university course. Assuming the FPGA at least has a media access controller (translates bits to analogue signals) it is not to hard to encode/decode ethernet frames. Sadly, on the top of my head I do not know of any open IP. We wrote our own, but it is closed.
- abjectcircle 10y agoI don't know about open IP, but it would be fairly straightforward but not trivial. Knowing verilog would be required, though, but it can be learned from a digital design book [1]. From there, you would probably want some experience in using the tools. For example, for Xilinx FPGAs, you could run through the Vivado tutorials. Then to design the IP you would design the state machines and logic to take data from one ethernet controller (for example, the Xilinx ethernet MAC [2]) and send it to another. The actual verilog would not be especially complex, however interfacing with the ethernet controllers and other peripherals would take some time. [1] Such as https://www.amazon.com/Logic-Design-Verification-SystemVerilog-Revised/dp/1523364025 https://www.amazon.com/Logic-Design-Verification-SystemVeril... [2] https://www.xilinx.com/support/documentation/ip_documentation/tri_mode_ethernet_mac/v8_2/pg051-tri-mode-eth-mac.pdf https://www.xilinx.com/support/documentation/ip_documentatio...
- nickpsecurity 10y agoAdd MACsec while you're at it to immunize you against attacks involving taps or a subset of compromised Ethernet NIC's. Well, a subset of it maybe as it got complicated like some other standards. https://www.juniper.net/documentation/en_US/junos15.1/topics/concept/macsec.html https://www.juniper.net/documentation/en_US/junos15.1/topics...
- scott_wilson46 10y agoIn actual fact for Xilinx based FPGA's this is quite straightforward. An example for 10G Base R: You can get Xilinx's component for their pma/pcs for 10g base-r ethernet for free from vivado and stick one of the macs from open cores on the end of it (probably this: http://opencores.org/project,xge_ll_mac http://opencores.org/project,xge_ll_mac - I used it for prototyping and it seems to work (before creating my own pcs/pma block and mac to cut down the latency) Once you have that, then you would need to deal with the ethernet frames streaming through the FPGA, probably 64-bits at a time at 156MHz for 10G, so you need to pull out the fields you are interested in (like mac addresses, ip addresses, etc). You can buffer the incoming packet into a FIFO whilst waiting for the stuff you want to filter on. Once you have all your fields you can decide whether you want to pass the packet through to the tx side or not (I usually read the packet out of the FIFO either way and just hold the valid low for packets I don't want to send). Hope this makes sense!