[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] issue with iptables antispoofing rules in xen4.8 generetab by vif-bridge and vif-common.sh


  • To: spi@xxxxxxxxx
  • From: Wiebe Cazemier <wiebe@xxxxxxxxxxxx>
  • Date: Mon, 26 Mar 2018 19:58:57 +0200 (CEST)
  • Cc: xen-users@xxxxxxxxxxxxxxxxxxxx
  • Delivery-date: Mon, 26 Mar 2018 18:00:30 +0000
  • List-id: Xen user discussion <xen-users.lists.xenproject.org>
  • Thread-index: otu2CYMPQEAQUWlZ7rIs2rLmROK1yQ==
  • Thread-topic: issue with iptables antispoofing rules in xen4.8 generetab by vif-bridge and vif-common.sh

> From: spi@xxxxxxxxx
> To: xen-users@xxxxxxxxxxxxxxxxxxxx
> Sent: Saturday, 24 March, 2018 16:03:03
> Subject: [Xen-users] issue with iptables antispoofing rules in xen4.8 
> generetab
> by vif-bridge and vif-common.sh
>
> Hi all
>
> I filed this issue with the Debian user-list as well but as I think it is not
> Debian related I file it here as well.
>
> I have issues with the on domU startup automatically generated
> antispoofing rules by
>
> /etc/xen/scripts/vif-bridge and
> /etc/xen/scripts/vif-common.sh

On a side-note, the recommended way of configuring the network is doing it 
manually (i.e. defining the bridge in your OS configuration files). The issues 
with the script are numerous. For one, you can't do (the equivalent of) 
'/etc/init.d/networking restart', because then the Xen script is not run. Or 
you iptables state will fail because network devices aren't there yet. Etc.

See: 
https://wiki.xenproject.org/wiki/Xen_Networking#Setting_up_bridged_networking

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-users

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.