WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] iptables and state matches (established, related)

Hi,

I'm just about to setup xen together with iptables, so this statement slightly 
worries me.

Do you have more details (or a link to them) about this problem ? What are the 
exact symptoms and in which circumstances do the occur ?

For example, is this a problem when using iptables in dom0 or in domU or in 
both ?

Or does it only happen when trying to apply connection tracking on the bridge 
level ?

Geert

On Saturday 28 April 2007 14:49, John Hannfield wrote:
> This is a known problem with Xen 3.0.x  and iptables connection tracking.
> Connection tracking and state filtering only works as long as xen is
> not running.
> Try doing this:
>
> echo "0" >/proc/sys/net/bridge/bridge-nf-call-iptables
>
> That fixed it for me.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>