[libvirt] iptables rules for a vm

Andrew Cathrow acathrow at redhat.com
Tue Dec 9 22:51:28 UTC 2008

On Tue, 2008-12-09 at 17:30 -0500, Karl Wirth wrote:

> Hello,
> I have kicked around an idea before with some of you about
> iptables...basically being able to have iptables rules that are
> associated with the metadata around a particular vm, then apply those to
> the host iptables when the vm is spun up or migrated to that host.  

Especially the interesting issues around taking the nf/ip_conntrack data
and making sure that state information is correctly migrated.

> I emailed with James he thinks the pieces are there but integration work
> is needed (as well as the central management).  Would someone be willing
> to help me understand what major pieces of work would be needed to make
> this possible?
> Regards,
> Karl
> --
> Libvir-list mailing list
> Libvir-list at redhat.com
> https://www.redhat.com/mailman/listinfo/libvir-list

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20081209/15e9acb3/attachment-0001.htm>

More information about the libvir-list mailing list