[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] Force traffic out one interface

On Sun, Jun 13, 2010 at 10:45 PM, Jonathan Tripathy <jonnyt@xxxxxxxxxxx> wrote:
> Hi Everyone,
> Does anyone know any rules that I could use (using iptable, ebtables, or
> otherwise) that could force all traffic coming from a guest to go out via a
> particular interface? I wish to stop "inter-guest" communication, without
> going via my firewall first.

IIRC Xen bridged networking by default passes domU traffic through the
bridge on dom0 (even for inter-guest communications). Try setting up
some rules there (i.e. make dom0 your firewall).

If you want to use an external firewall (not in dom0), then no, I
don't know of any way to do that.


Xen-users mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.