OpenVZ Forum


Home » General » Support » Firewall in the VE
icon5.gif  Firewall in the VE [message #10085] Wed, 07 February 2007 19:28 Go to next message
gral is currently offline  gral
Messages: 34
Registered: May 2006
Member

Hi everybody,

My question is about is necessary install a firewall in each VE, or only installing into the Hardware Node is enough to keep secure the VEs .

Is because im using 10 vps and in a few of them i need to stop the iptables to send mails, or the ICMP to the vps inst very good from a lot of connections, and installing a firewall can make worse the situation.

That's all, any expierence will be helpfully

gRaL Very Happy


Argentina
--Vz--
Re: Firewall in the VE [message #10090 is a reply to message #10085] Thu, 08 February 2007 04:01 Go to previous messageGo to next message
rickb is currently offline  rickb
Messages: 368
Registered: October 2006
Senior Member
Hi Argentina. The end result will be the same- the packets filtered by the firewall will not reach your applications.

You can do this on the HN forward table or the VE input table. To me, it only depends where you want logging (if any), where you want to be able to troubleshoot (if the packet is dropped on HN, VE can't troubleshoot it), and security (if your VE is managed by somone else, you want to filter VE traffic without them being able to override).

Hope this points you in the right direction!
Rick Blundell


-------------
Common Terms I post with: http://wiki.openvz.org/Category:Definitions

UBC. Learn it, love it, live it: http://wiki.openvz.org/Proc/user_beancounters
Re: Firewall in the VE [message #10094 is a reply to message #10085] Thu, 08 February 2007 07:23 Go to previous message
stoffell is currently offline  stoffell
Messages: 16
Registered: February 2007
Location: Belgium
Junior Member
You could use a simple setup of shorewall to do some basic firewalling, at least it makes it easier to change rules. So even when you set it up on each VE it's pretty manageable and consistent across VE's..

cheers
Previous Topic: *SOLVED* "Private area already exists" ?
Next Topic: *SOLVED* WARNING: Function proxy_arp
Goto Forum:
  


Current Time: Tue Jul 30 02:23:06 GMT 2024

Total time taken to generate the page: 0.02834 seconds