OpenVZ Forum

Home » Mailing lists » Users » Multiple bridges and firewalls
Multiple bridges and firewalls [message #31622] Fri, 04 July 2008 08:47
dietmar is currently offline  dietmar
Messages: 54
Registered: March 2007
Hi all,

with the new vzctl bridge patch sent yesterday it is easy to build up
hosts with complex 'virtual' networks. In Proxmox VE we have 9 bridges -
each CT can connect to one or more bridges. 

I guess in theory it is possible to run a fully functional firewall
inside a CT. Does somebody has experiences with that?

Also, when you assign ip addresses to the bridges, the host routes
between those bridges. If you want to restrict traffic you need to setup
a firewall on the host. I just tried shorewall, and it seems to work
perfectly. Does somebody else using shorewall with openvz host? - does
it work reliable? Are there other 'simple' solutions besides shorewall?

- Dietmar
Previous Topic: memory leak in 2.6.18 ovz kernels
Next Topic: LVS (ip_vs) inside VE?
Goto Forum:

Current Time: Thu Jan 23 05:26:48 GMT 2020