[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] issue with iptables antispoofing rules in xen4.8 generetab by vif-bridge and vif-common.sh



>> I filed this issue with the Debian user-list as well but as I think it is not
>> Debian related I file it here as well.
>>
>> I have issues with the on domU startup automatically generated
>> antispoofing rules by
>>
>> /etc/xen/scripts/vif-bridge and
>> /etc/xen/scripts/vif-common.sh
> 
> On a side-note, the recommended way of configuring the network is doing it 
> manually (i.e. defining the bridge in your OS configuration files). The 
> issues with the script are numerous. For one, you can't do (the equivalent 
> of) '/etc/init.d/networking restart', because then the Xen script is not run. 
> Or you iptables state will fail because network devices aren't there yet. Etc.
> 
> See: 
> https://wiki.xenproject.org/wiki/Xen_Networking#Setting_up_bridged_networking
> 
That's exactly how I configure my bridges - manually in Debian's
/etc/neworking/interfaces file. But point taken, it seems to make more
sense to configure iptables rules manually.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-users

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.