WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Re; Firewalling tables ...

To: Xen-Users <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: [Xen-users] Re; Firewalling tables ...
From: Gareth Bult <gareth@xxxxxxxxxxxxx>
Date: Sat, 19 Jan 2008 03:26:07 +0000 (GMT)
Delivery-date: Fri, 18 Jan 2008 19:26:57 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Hi,

I seem to have a firewalling problems under XEN, I'm getting packet combinations I can't see to match ..

Can anyone give me an iptables or even better a "firehol" rule that will match something like;

kernel: 'PASS-unknown:'IN=xenbr1 OUT=xenbr1 PHYSIN=peth1 PHYSOUT=vif3.1 SRC="" DST=224.0.0.1 LEN=68 TTL=1 ID=1884 PROTO=ICMP

???

In firehol I'm expecting ;

router local inface xenbr1 outface xenbr1
    route all accept

To stop logging these packets, but it's not generating a match ...

tia
Gareth.
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-users] Re; Firewalling tables ..., Gareth Bult <=