This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


Re: [Xen-users] ebtables tying mac to ip problem

On Fri, Apr 03, 2009 at 06:04:29PM +0100, David wrote:

> Unfortunately i still cant get it to work. it seems to be a problem with
> /sbin/ebtables -P FORWARD DROP

Could you provide some ebtables logs?

> if i change this to  /sbin/ebtables -P FORWARD  then it starts working again
> but i can change ip address etc on the guest

There have to be DROP policy on the end of chain (or similar DROP rule).
It's preventing malicious traffic. All "good" network packets should hit
some ACCEPT rule before reaching end of FORWARD/INPUT chain.
> Does the vif-bridge patch still apply for this setup?

> Will i start from scratch and try to build up a set of rules for this
> situation? i'm sure this will fit into most xen networking situations as
> this setup is popular.

Sounds useful.

Great software without the knowledge to run it is pretty useless.
(Linux Gazette #1)

Xen-users mailing list