OpenVZ Forum


Home » Mailing lists » Users » Connection Tracking inside a VPS
Re: Connection Tracking inside a VPS [message #44180 is a reply to message #44172] Wed, 23 November 2011 11:01 Go to previous messageGo to previous message
MailingListe is currently offline  MailingListe
Messages: 29
Registered: May 2008
Junior Member
Zitat von Daniel Bauer <mlist@dsb-gmbh.de>:

> Hi @all,
>
> I tried to do a firewall inside a VPS. I inserted in the .conf file
> a line like this
> IPTABLES="ip_conntrack ip_...

To which *.conf file have you added this? It is needed in vz.conf so
the modules get loaded by starting OpenVZ at the HN. You will also
need ipt_filter as far as i remember. You can try iptables with
conntrack on the HN, if it works there it should work inside VE too.
But don't try it with IPv6.

> and tried to use the connection tacking like this
> root@gw:~# iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
> iptables: No chain/target/match by that name.
>
> but it looks like there is no module for connection tracking.

Check with lsmod on the HN what is loaded. The VE is not able to load
any modules on demand.

Regards

Andreas
  • Attachment: smime.p7s
    (Size: 6.03KB, Downloaded 374 times)
 
Read Message
Read Message
Read Message
Previous Topic: Guest disk quota
Next Topic: Re: Re: Guest disk quota (Solved)
Goto Forum:
  


Current Time: Sat Aug 02 06:26:39 GMT 2025

Total time taken to generate the page: 1.04941 seconds