OpenVZ Forum


Home » General » Support » iptables in vps or on the host node
iptables in vps or on the host node [message #2038] Thu, 16 March 2006 03:28 Go to next message
midair77 is currently offline  midair77
Messages: 2
Registered: March 2006
Junior Member
Hi, all. I just started learning how to set up openVZ and it is quite good compared to vserver.

I would like to know where iptables should be set up to provide security for vps. Should I set up iptables invidually for each vps or one iptables in hardware node to cover all?

Please provide some directions.

Thank you for your helps.
Re: iptables in vps or on the host node [message #2041 is a reply to message #2038] Thu, 16 March 2006 08:17 Go to previous messageGo to next message
kir is currently offline  kir
Messages: 1645
Registered: August 2005
Location: Moscow, Russia
Senior Member

You can actually do it both ways. If you want to close some ports for all the VPSs, the best place to do that would be on hardware node itself for obvious reasons (less rules).

If you want to set some VPS-specific rules, you can do it either on the host node or from within a VPS. The major difference here in the second case VPS owner can modify those rules.

Also note that you can not use all of the iptables modules inside a VPS, just some of them which are virtualized. man vzctl should tell you which ones are possible.


Kir Kolyshkin
http://static.openvz.org/userbars/openvz-developer.png
Re: iptables in vps or on the host node [message #2050 is a reply to message #2041] Fri, 17 March 2006 01:09 Go to previous messageGo to next message
midair77 is currently offline  midair77
Messages: 2
Registered: March 2006
Junior Member
Thank kir for your clear and helpful reply.
Re: iptables in vps or on the host node [message #2051 is a reply to message #2041] Fri, 17 March 2006 02:41 Go to previous message
jbond007 is currently offline  jbond007
Messages: 78
Registered: January 2006
Location: Miami
Member
if you need secure the vps
i think will be the best way use iptable

vzctl exec vpsid and the iptable command

Thank you

Previous Topic: using network aliases
Next Topic: OpenVZ on CentOS 4.2
Goto Forum:
  


Current Time: Sat Jul 13 14:39:18 GMT 2024

Total time taken to generate the page: 0.02235 seconds