[pve-devel] pve-firewall : add ipfilter protection
Alexandre DERUMIER
aderumier at odiso.com
Wed Jun 11 12:37:56 CEST 2014
I'll check that tomorrow, I'm super busy at work today.
----- Mail original -----
De: "Dietmar Maurer" <dietmar at proxmox.com>
À: "Alexandre DERUMIER" <aderumier at odiso.com>, "Stefan Priebe - Profihost AG" <s.priebe at profihost.ag>
Cc: pve-devel at pve.proxmox.com
Envoyé: Mercredi 11 Juin 2014 10:07:18
Objet: RE: [pve-devel] pve-firewall : add ipfilter protection
> >>Would it make sense to also allow ip/mask notation so pve knows more about
> the network? May be display user ip settings?
>
> Don't have tested, but I think it should work. I'll test that today.
I just applied a simplified version of your patch.
I simply apply the filter if the VM firewall configuration defines a ipset named 'ipfilter'.
This works with venet and tap devices, and does not require any change in qemu-server config.
Does that work for you?
More information about the pve-devel
mailing list