Port-xen archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
properly ipf config on dom0
Hi All!
May be wrong maillist but...
I have dom0 with NetBSD and some domU with other OSes.
external dom0 interface nfe0 bridged to one of domU. IPF configured to
check domU IP-address at nfe0 but traffic for domU still not filtered
and not logged by IPF.
As I understand traffic comes to nfe0, then driver (?) discover packet
addressed to IP-address (or MAC?) owned by domU and send it to domU via
bridge without putting it into IPF input queue.
Is it correct?
If so, then I need to recompile kernel with BRIDGE_IPF option?
If not -- how I must protect my domU by IPF on dom0 ?
Advice me please
--
CU,
Victor Gamov
begin:vcard
fn:Victor Gmov
n:Gmov;Victor
email;internet:vit%euro-comm.net@localhost
tel;work:sip:04800112%euro-comm.net@localhost
x-mozilla-html:FALSE
version:2.1
end:vcard
Home |
Main Index |
Thread Index |
Old Index