WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] xen 3.0.3: Problem with setting up iptables (fwbuilder)

To: Xen Users <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: [Xen-users] xen 3.0.3: Problem with setting up iptables (fwbuilder)
From: Denny Schierz <cuall@xxxxxx>
Date: Mon, 13 Nov 2006 14:27:18 +0100
Delivery-date: Mon, 13 Nov 2006 05:35:07 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
hi,

on Friday i did a upgrade vom 3.0.2 to 3.0.3. I get in trouble with my
IPTables rule-set, generated with the fbuilder (2.0.9) tool.

I use as inside device xenbr0 (private-ip) and ppp0 as outside. After
upgrading the scripts from the install, everything blocked, after
starting the firewall. I saw, that xenbr0 does not have any ip, but
eth0, so i changed the inside device from xenbr0 to eth0. Iptraf tolds
me, that everything from the network, runs over eth0 to ppp0. But, after
restarting the firewall, with the changes, the connection was blocked
again (from inside to the xen host).

Its very confusing and there must be something, i did not realize. I
have xenbr0 (without ip), peth0(without ip too), eth0 and some vifs. If
i don't start the firewall, the connection works, but nat. Means, nobody
is able, to get internet working via nat. But that was, what i expected.

Now i getting everything working again, after changing the scripts from
3.0.3 back to 3.0.2, but it makes me nervous, cause i did not understand
the new setup in xen 3.0.3.

could anybody explain me, with some hinds, the new setup? Some iptables
rules, as example, would helping me too.

thanks a lot.

cu denny

-- 
Sicherheit verständlich http://www.sides.de
GnuPG Key
http://pgpkeys.pca.dfn.de:11371/pks/lookup?op=get&search=0x2A5CE192AB7D3FE0

Attachment: signature.asc
Description: Dies ist ein digital signierter Nachrichtenteil

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-users] xen 3.0.3: Problem with setting up iptables (fwbuilder), Denny Schierz <=