WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Firewalls

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello list,

I'm having trouble getting my firewall working on dom0. I do not have
any domUs setup yet, it is just the primary dom0 running. 

I had a firewall script that worked great and did what I needed it to
before I installed Xen. However, after installing Xen, it seems to
block all incoming traffic (including pings). Previously it allowed
incoming ssh, smtp, http, etc. The script uses iptables. 

I have not changed anything in the firewall script. Since it still uses
the same ip address and the ip is still assigned to the same eth0 NIC,
it seems like I shouldn't need to change anything in the firewall
script. But it doesn't seem to be working that way. 

Do I need to tell the firewall about any of the xenbrX or vifX.X
interfaces or anything to get it to work? Ip_tables is obviously
compiled into the kernel, and I can see it is loaded when I check with
an lsmod. I can post the iptables rules here if needed, but didn't want
to make the e-mail extra long if it's not needed.

TIA,
Jacob
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFENnFakpJ43hY3cTURAujyAJ0XkswA2nj5DgQbY9+xt0bZdbiSSQCfXe0U
uUgpm3TAyz4UQOrbpwjoGQk=
=gIiT
-----END PGP SIGNATURE-----
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users