[pve-devel] pve-firewall : ebtables

Dietmar Maurer dietmar at proxmox.com
Tue Jul 15 12:32:35 CEST 2014


> >>2.) Generally i would like to see the macfilter enabled for iptables
> >>and ebtables even if the network card has firewall=0 but the vm has
> >>firewall=1. Does this makes sense?
> 
> Just send a patch.

I am quit unsure if this makes sense. It works the opposite way:

macfilter works even if the vm has firewall=0

So why do we want to filter macs if the admin disabled the whole firewall on the interface?


More information about the pve-devel mailing list