OpenVZ Forum


Home » General » Support » Firewall in the VE
Re: Firewall in the VE [message #10090 is a reply to message #10085] Thu, 08 February 2007 04:01 Go to previous messageGo to previous message
rickb is currently offline  rickb
Messages: 368
Registered: October 2006
Senior Member
Hi Argentina. The end result will be the same- the packets filtered by the firewall will not reach your applications.

You can do this on the HN forward table or the VE input table. To me, it only depends where you want logging (if any), where you want to be able to troubleshoot (if the packet is dropped on HN, VE can't troubleshoot it), and security (if your VE is managed by somone else, you want to filter VE traffic without them being able to override).

Hope this points you in the right direction!
Rick Blundell


-------------
Common Terms I post with: http://wiki.openvz.org/Category:Definitions

UBC. Learn it, love it, live it: http://wiki.openvz.org/Proc/user_beancounters
 
Read Message icon5.gif
Read Message
Read Message
Previous Topic: *SOLVED* "Private area already exists" ?
Next Topic: *SOLVED* WARNING: Function proxy_arp
Goto Forum:
  


Current Time: Tue Jul 30 12:24:41 GMT 2024

Total time taken to generate the page: 0.02765 seconds