[pve-devel] pve-firewall : add ipfilter protection

Dietmar Maurer dietmar at proxmox.com
Wed Jun 11 17:45:49 CEST 2014


> Think of private ip space may be there is the same networks in net0 and net1.

I think it is a very bad network design - and not very common? Do you really use such setup? If so, why?

> Or traffic on net1 is free of charge but traffic on net0 isn't someone could use a
> 2nd vm as a router.

how exactly?

> Or someone can use a private ip range but only on net1 which is last limited to
> 10mb/s and not on net0 which is 10gb/s.

Traffic is not routed if you try to use the wrong interface, so I can't see how that happens.





More information about the pve-devel mailing list