OpenVZ Forum


Home » General » Support » Updating VZ.CONF and restarting without rebooting VMs (Updating vz.conf)
Updating VZ.CONF and restarting without rebooting VMs [message #45009] Fri, 20 January 2012 13:47 Go to next message
WizJames is currently offline  WizJames
Messages: 1
Registered: January 2012
Location: Boston
Junior Member
I've added a few lines in vz.conf so a friend of mine can do masquerading with iptables. I belive in order to refresh /etc/vz/vz.conf I need to restart the vz service.

1.) Is there an alternative way to restart/update the vz.conf
2.) If there isn't.... How can I without effecting the current VM's loaded.

Thanks in advance.
Re: Updating VZ.CONF and restarting without rebooting VMs [message #45027 is a reply to message #45009] Sun, 22 January 2012 11:34 Go to previous messageGo to next message
insider
Messages: 11
Registered: January 2012
Junior Member
You can include iptables modules in the container config file and restart just this one container, not all vz service and other containers.
But in this case you have to list ALL ip_tables modules you need in the container config file, even modules listed in the main vz.conf file.

[Updated on: Sun, 22 January 2012 11:35]

Report message to a moderator

Re: Updating VZ.CONF and restarting without rebooting VMs [message #45065 is a reply to message #45009] Wed, 25 January 2012 17:59 Go to previous message
mustardman is currently offline  mustardman
Messages: 91
Registered: October 2009
Member
If you are asking how to load those additional iptables kernel modules without restarting the node or the openvz service, that is very simple.

From a command line on the Node we can view the already loaded iptables kernel modules.

cat /proc/net/ip_tables_matches

udp
tcp
owner
state
.
.
.


Now load the new iptables kernel modules that you have added to /etc/sysconfig/iptables-config or to etc/vz/vz.conf. So, for example if we have added ipt_recent to either of those 2 config files then:

modprobe ipt_recent


Now view loaded iptables kernel modules again and you will see the new module load.

cat /proc/net/ip_tables_matches

recent
udp
tcp
owner
state
.
.
.


This document explains the difference between those 2 config files.
http://download.swsoft.com/virtuozzo/virtuozzo4.0/docs/en/li n/VzLinuxUG/6167.htm

[Updated on: Wed, 25 January 2012 18:06]

Report message to a moderator

Previous Topic: cannot run ntpd as non root user under VE[Solved]
Next Topic: bond0 if in a container
Goto Forum:
  


Current Time: Sun Jun 16 07:14:23 GMT 2024

Total time taken to generate the page: 0.03788 seconds