[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Xen-users] Xen 3.4.2 networking help

  • To: "Simon Hobson" <linux@xxxxxxxxxxxxxxxx>, <Xen-users@xxxxxxxxxxxxxxxxxxx>
  • From: "Jonathan Tripathy" <jonnyt@xxxxxxxxxxx>
  • Date: Wed, 27 Oct 2010 10:26:12 +0100
  • Cc:
  • Delivery-date: Wed, 27 Oct 2010 02:28:52 -0700
  • List-id: Xen user discussion <xen-users.lists.xensource.com>
  • Thread-index: Act1uIBSEbvcbo8+RIqcrNxbsdxwcwAAH6OF
  • Thread-topic: [Xen-users] Xen 3.4.2 networking help

>If you are refering to the OUTPUT chain of the Dom0 itself, surely
>you wouldn't use physdev at all? Wouldn't you just use "iptables -A
>OUTPUT -o ethx ...."?

Dunno about iptables specifics - I only use Shorewall and I know it's
a limitation. But isn't "-o ethx" a device match ?
If there was a way around the limitation, I'm sure Tom Eastep would
have figured it out.
Hi Simon,
Yes, "-o ethx" is indeed a device match, but it works differently to physdev, which really only works well on fordwarded traffic (Although I think it is supposed to work on all bridged traffic)
Can you please post a link to information about this? I can't find anything on Google about this.
Xen-users mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.