Luciano Miguel Ferreira Rocha <strange@xxxxxxxxxxxxx> wrote:
>> The interaction with host firewall rules has always been a bit icky, not
>> least because the xen network scripts typically run after the host's
>> firewall scripts (and rename the network device). I've never understood
>> what happens to the firewall rules - do they stay with the old eth0 (now
>> peth0) or do they now apply to the new device name?
> IIRC, interface names in iptables rules are symbolic, so eth0 means what
> currently stands for eth0.

Correct.  Only the interface name is compared.

