[pve-devel] RFC : iptables implementation

Dietmar Maurer dietmar at proxmox.com
Wed Jan 22 17:03:38 CET 2014


> FORWARD -> proxmoxfw-chain ->jump in tap chain1
>                            <-return or drop
>                            ->jump in tap chain2
>                            <-return or drop
> 
>                            ->ACCEPT
> 
> 
> don't known if it's better than

Above would only handle traffic originated from a VM and skip traffic from outside (eth0)?



More information about the pve-devel mailing list