|   | 
      | 
  
  
      | 
      | 
  
 
     | 
    | 
  
  
     | 
    | 
  
  
    |   | 
      | 
  
  
    | 
         
xen-users
Re: [Xen-users] dom0 can see connections from domU-s
 
Fajar A. Nugraha wrote:
 
On Tue, Aug 25, 2009 at 5:48 AM, Deyan Chepishev<dchepishev@xxxxxxxxx> wrote:
   
Hello,
I have a little problem.
I can see all the guest (domU) connections in dom0's /proc/net/ip_conntrack.
As you can imagine the conntrack table starts to get filled when lots of
connections are made on domU machines. Is there a way to stop this behavior?
     
 
What is the value of /proc/sys/net/bridge/bridge-nf-call-iptables ?
   
 
The value is:
cat /proc/sys/net/bridge/bridge-nf-call-iptables
1
 It looks like changing it ot 0 fixes my problems. The number of rows is 
going down.
Thank you
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
 
 |   
 
 | 
    | 
  
  
    |   | 
    |