[pve-devel] pve-firewall : add ipfilter protection

Alexandre DERUMIER aderumier at odiso.com
Wed Jun 11 12:37:56 CEST 2014


I'll check that tomorrow, I'm super busy at work today.


----- Mail original ----- 

De: "Dietmar Maurer" <dietmar at proxmox.com> 
À: "Alexandre DERUMIER" <aderumier at odiso.com>, "Stefan Priebe - Profihost AG" <s.priebe at profihost.ag> 
Cc: pve-devel at pve.proxmox.com 
Envoyé: Mercredi 11 Juin 2014 10:07:18 
Objet: RE: [pve-devel] pve-firewall : add ipfilter protection 

> >>Would it make sense to also allow ip/mask notation so pve knows more about 
> the network? May be display user ip settings? 
> 
> Don't have tested, but I think it should work. I'll test that today. 

I just applied a simplified version of your patch. 

I simply apply the filter if the VM firewall configuration defines a ipset named 'ipfilter'. 

This works with venet and tap devices, and does not require any change in qemu-server config. 

Does that work for you? 



More information about the pve-devel mailing list