[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] iptables problem


  • To: Ivan Lisenkov <ivan@xxxxxxxxx>
  • From: Sergey Smirnov <sergey.a.smirnov@xxxxxxxxx>
  • Date: Wed, 14 Oct 2009 19:37:10 +0400
  • Cc: xen-users@xxxxxxxxxxxxxxxxxxx
  • Delivery-date: Wed, 14 Oct 2009 08:38:32 -0700
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; b=Pot0wZP3t30JT3oyKmyJ6MrOzdfe+tjXyuVPH9bZayy3sDtcsmztdGNDVXg6UR7IjL O2jmkulJ0+Ne3RJGm/MkNYCXAqKYdIwumtYDtuR7koCqe8/4m4bl5adESmES0QSizvLP C9rzI4eDLHeCLLEJAEd8xLSOVLTIsk6uD66Jc=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Hi Ivan,

maybe you should add the permanent rules in the bottom of your iptables configuration like this? -

-A FORWARDÂ--sourceÂdomU_ipÂ--jumpÂACCEPT
-A FORWARDÂ--destinationÂdomU_ipÂ--jumpÂACCEPT

so it will be works in any time without additional rules added by xen scripts.
I use the same configuration.

On Tue, Oct 13, 2009 at 2:31 PM, Ivan Lisenkov <ivan@xxxxxxxxx> wrote:
Dear xen users,

I am using xen 3.3.1 on opensuse 11.1. After creating a domU with 2 nics two iptables rules are created by default:

-A FORWARD -s XX.XX.XX.24/32 -m physdev --physdev-in vif77.0 -j ACCEPT
-A FORWARD -p udp -m physdev --physdev-in vif77.0 -m udp --sport 68 --dport 67 -j ACCEPT
-A FORWARD -s XX.XX.XX.25/32 -m physdev --physdev-in vif77.1 -j ACCEPT
-A FORWARD -p udp -m physdev --physdev-in vif77.1 -m udp --sport 68 --dport 67 -j ACCEPT

The rules seems logical, but one of them does no work! I can't ping XX.XX.XX.24 from outside. But if I change the rule manulally to:

-A FORWARD -s 188.40.226.24/32 -m physdev --physdev-in vif77.1 -j ACCEPT

everything works. This seems unlogical, because first ip is bounded to second nic, but works. The problem is that I have to change the rules every I reboot domu.

Any ideas how to fix it?


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users



--
Serg Smirnov
email/xmpp: Sergey.A.Smirnov@xxxxxxxxx

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.