[libvirt] [libvirt PATCHv6 1/1] add DHCP snooping

David Stevens dlstevens at us.ibm.com
Thu Mar 22 20:23:01 UTC 2012


Stefan Berger/Watson/IBM wrote on 03/22/2012 12:22:20 PM:

> 
> I tried it. It doesn't apply more than one IP address. The code also
> doesn't apply cleanly to the tip.
> 
>    Stefan

Stefan,
        I did a git pull yesterday to which this patch is
applied; here is the last entry before the patch:

commit 25fb4c65a54e3c34c8084b2d49b888d11685a973
Author: Eric Blake <eblake at redhat.com>
Date:   Tue Mar 20 17:04:38 2012 -0600

    build: drop a painfully long gnulib test

        Am I using the wrong git tree, or can you be
more specific about the errors you're seeing?
        The last I looked at this there was no multiple
address support and this code is not attempting to add it.
If you're saying that ip_learning, which this optionally substitutes
for, now supports multiple addresses, I can look at adding
it. The goal of this patch is simply to use only valid
DHCP leases as the basis for anti-spoofing rules as a more
secure method than the existing learning code.

                                                +-DLS




More information about the libvir-list mailing list