[pve-devel] pve-firewall : add ipfilter protection

Stefan Priebe - Profihost AG s.priebe at profihost.ag
Fri Jun 13 14:45:12 CEST 2014


> Am 12.06.2014 10:41, schrieb Dietmar Maurer:
>>
>>
>>> -----Original Message-----
>>> From: Alexandre DERUMIER [mailto:aderumier at odiso.com]
>>> Sent: Donnerstag, 12. Juni 2014 10:37
>>> To: Dietmar Maurer
>>> Cc: pve-devel at pve.proxmox.com; Stefan Priebe
>>> Subject: Re: [pve-devel] pve-firewall : add ipfilter protection
>>>
>>> What is the netid for a openvz veth interface ?
>>>
>>
>> eth0, eth1, ...
>>
>>> (maybe can we add an example ?)
>>
>> please add (send a patch).
>>

OK seems my testing is wrong.

What is did:

/etc/pve/firewall/2004.fw:
[IPSET ipfilter-net0]
10.10.28.5

I then enabled the Firewall for this VM.

The VM has now 10.10.28.4 on net0 - but the VM is still able to make
traffic with 10.10.28.4. Anything i did wrong?

Stefan







More information about the pve-devel mailing list