[pve-devel] pve-firewall : iptables V2

Alexandre DERUMIER aderumier at odiso.com
Thu Feb 13 17:27:12 CET 2014


>>AFAIK iptables support interface wildcards, so you can use 'tap100i+' to match all interfaces for VM 100. 
>>Would that help to optimize things further?

I'm not sure, because you can have tap interfaces from same vm on differents bridge.


----- Mail original ----- 

De: "Dietmar Maurer" <dietmar at proxmox.com> 
À: "Alexandre DERUMIER" <aderumier at odiso.com>, pve-devel at pve.proxmox.com 
Envoyé: Jeudi 13 Février 2014 12:05:34 
Objet: RE: [pve-devel] pve-firewall : iptables V2 

> any comments for theses patches ? 

AFAIK iptables support interface wildcards, so you can use 'tap100i+' to match all interfaces for VM 100. 
Would that help to optimize things further? 



More information about the pve-devel mailing list