|
|
|
|
|
|
|
|
|
|
xen-users
Re: [Xen-users] vif-antispoof
Hi Mats,
Mats Engstrom schrieb:
Hi Dirk,
I also had problems getting it to work when I tried it some months ago. As
far as I can remember I had just the same symptoms as you.
In order to get have the iptables correctly setup by vif-bridge in
antispoof-mode the kernel must have the pysdev option in the netfilter
section enabled and/or loaded as a module. When compiled into the kernel the
line in the .config -file should look lite this:
CONFIG_IP_NF_MATCH_PHYSDEV=y
After recompling and installing a new Dom0-kernel it worked just fine.
Yes, you are right, that's it. Thanks!
But one more question: How did you find out THAT? I am not really into
netfilter yet, and there is no hint in the docs I found.
Ah, and still on more question: Did you test/do you know if the
antispoof feature prevents IP spoofing only or ARP spoofing as well?
Dirk
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
|
|
|
|
|