Re: iptables apf moblock veth0 [message #28501 is a reply to message #28486] |
Fri, 21 March 2008 00:15 |
locutius
Messages: 125 Registered: August 2007
|
Senior Member |
|
|
i have now had the opportunity to test my experimental setup for 48 hours and i have discovered it is working without any need to edit the moblock start script. iptables by default filters ALL interfaces including virtual interfaces
the design of the default moblock start script is excellent and does the job straight out of the box
i confirm i have a webserver running moblock and apf in 2 instances of iptables in series, my method:
1. install OpenVZ
2. create a CT (it can be as big as the HN)
3. install moblock in the HN
4. install apf in the CT
5. run your webservices from the CT
there are numerous other benefits to using server virtualization technology and currently i do not see a downside
[Updated on: Sat, 22 March 2008 12:31] Report message to a moderator
|
|
|