# Multi client L2 host / intercept

**URL:** <https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167>\
**Category:** Ziti Overlay\
**Created:** [October 5, 2026, 11:26am UTC](https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167 "2026-10-05T11:26:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![FP0710](https://avatars.discourse-cdn.com/v4/letter/f/e8c25b/32.png) [@FP0710](https://openziti.discourse.group/u/FP0710)\
**Post date:** [October 5, 2026, 11:26am UTC](https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167/1 "2026-10-05T11:26:16Z")

</div>

I was wondering if somebody managed to get multiple identities Dial/connect to the same layer2 host service at once.

A 1:1 connections works fine, but in the moment a 2nd client starts a ping for example , the connection is split between the 2 and it gets messy.

both hosts and client1, client2 use **ziti-edge-tunel (vv1.18.7)**

given the fact that the host should be kept in the dark, I also tried spinning up a ziti-router on the host in "host mode". yet client are not able to connect to it .

```auto
(1916131)[1533.821] INFO ziti-sdk:channel.c:981 reconnect_channel() ch[2] reconnecting in 127437ms (attempt = 20)                                                                 

```

**L2-intercep service** catches `0x0800, 0x0806 , 0x8100 `frames

**L2-host service** has an `IFS` set (same name of a bridge on the host)

ziti controller / router versions 2.x

The whole idea is basically to Bridge multiple clients directly on a bridge on the host (ovpn tap style).

Thanks in advance

---

<div class="post-metadata">

**Author:** ![scareything](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/scareything/32/106_2.png) [@scareything](https://openziti.discourse.group/u/scareything)\
**Post date:** [October 5, 2026, 1:49pm UTC](https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167/2 "2026-10-05T13:49:27Z")

</div>

Hi and welcome to the OpenZiti discourse!

As you've discovered, the current l2 implementation only handles a single connection at a time. I created [https://github.com/openziti/ziti-tunnel-sdk-c/issues/1445](https://github.com/openziti/ziti-tunnel-sdk-c/issues/1445) to track this issue.

I think purely handling multiple l2 connections will be a pretty straightforward change. It's not clear to me from your post, so I'll ask if you also need the clients to reach each other through the service (so the hosting tunneler acts as a switch)? If so that will be a little more complicated but doable.

Thanks!

---

<div class="post-metadata">

**Author:** ![FP0710](https://avatars.discourse-cdn.com/v4/letter/f/e8c25b/32.png) [@FP0710](https://openziti.discourse.group/u/FP0710)\
**Post date:** [October 5, 2026, 2:24pm UTC](https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167/3 "2026-10-05T14:24:29Z")

</div>

Hi,

Thanks for creating the issue.

Seen from a security perspective, clients not seeing each other is a safer option, the important direction is from the client to the hosts bridge (or whatever is behind it)

Is there any way at the moment, to configure this scenario ? (by configuring ziti-router in host mode on the same host for example)

Thanks

---

<div class="post-metadata">

**Author:** ![scareything](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/scareything/32/106_2.png) [@scareything](https://openziti.discourse.group/u/scareything)\
**Post date:** [October 5, 2026, 3:34pm UTC](https://openziti.discourse.group/t/multi-client-l2-host-intercept/6167/4 "2026-10-05T15:34:40Z")

</div>

Thanks, that's helpful. Isolating clients is actually the simpler option: frames from a client go only to the host's interface, and frames from the host side go back to whichever client owns the destination mac.

Unfortunately multiple l2 clients is not currently possible with any tunneler. The router's built-in tunneler doesn't support l2 at all, and adding it would be a bigger change than adding the ability to ziti-edge-tunnel.
