OpenVZ Forum


Home » General » Discussions » Iptables on Host Node
Re: Iptables on Host Node [message #36805 is a reply to message #36340] Mon, 20 July 2009 23:30 Go to previous messageGo to previous message
irontowngeek is currently offline  irontowngeek
Messages: 20
Registered: January 2009
Junior Member
As a suggestion for an alternative to using IPTABLES syntax,I would like to recommend using SHOREWALL firewall on the Node server.
It has excellent docs,and makes it easier for a user,if they are not that familiar with working with IPTABLES syntax.(all you need to do,is edit certain config files.(zones,interfaces,SNAT,DNAT,traffic shaping,etc)
To answer your question,you are doing to have to DNAT the incoming source IP subnet/address,to reflect the IP address(s) that you need to re-direct towards a given VE container.
Before moving to SHOREWALL,I configured an init script upon bootup,that would lock down access to the Node,and then open up the ports I needed,or redirected to a VE.
I'm at a Windows workstation at the moment,and I will post this
setup I used before,in hopes it may be useful to you,or use a guide.
 
Read Message
Read Message
Read Message
Previous Topic: OpenVZ on multiple server
Next Topic: Virtuozzo XML API with PHP script
Goto Forum:
  


Current Time: Sat Sep 28 23:27:32 GMT 2024

Total time taken to generate the page: 0.04164 seconds