[pve-devel] loading nf_conntrack_ftp module by default ?

Alexandre DERUMIER aderumier at odiso.com
Mon May 19 13:15:13 CEST 2014


so,

iptables_module : module module module

Do we want to filter module names ?

(host.fw or cluster.fw ?)


----- Mail original ----- 

De: "Dietmar Maurer" <dietmar at proxmox.com> 
À: "Alexandre DERUMIER" <aderumier at odiso.com> 
Cc: pve-devel at pve.proxmox.com, "Daniel Hunsaker" <danhunsaker at gmail.com> 
Envoyé: Lundi 19 Mai 2014 12:45:46 
Objet: RE: [pve-devel] loading nf_conntrack_ftp module by default ? 

> >>Users already complain, so it is maybe better to do not autoload that for now. 
> 
> Maybe, can we simply add an helper section|options, in cluster.fw ? 
> 
> ftp_helper :1|0 
> other_helper : 1|0 

or same as openvz (man vz.conf): 

IPTABLES_MODULES="module module ..." 



More information about the pve-devel mailing list