WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Has anyone successfully set up a dhcp/iptables firewall in d

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] Has anyone successfully set up a dhcp/iptables firewall in dom0 NATing traffic from domU?
From: "Rich Brown" <rgsbrown@xxxxxxxxx>
Date: Tue, 12 Feb 2008 00:17:28 -0700
Delivery-date: Mon, 11 Feb 2008 23:18:03 -0800
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; bh=KV2DqzjyjQPp9VFvcF8Qv0H7dyyww9lIzjRjnGVU9m8=; b=v4m1NuaQR0QxUN2BT0MS8Zd1HLQTmRqKhqcX3TmeGzXghEkPiHuGiy2xKSR6o4LJc3gK50iYtwit5TG2x3B4m1ydW6EnQrdR/QOQAPJxG89WBpTzpFOpGpc9e3BdBxcheMAwytKrw4zrM/u90748KhNKNnvkWgXO0uNxQMFszME=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=jlYf7hgZ+KNfgdJjj/A82Iykzi4b7QeVa54pw73/0WKcTymxKnMPrHLhi5rplEwVOzs3LWb0K01hUe68JPszSHxvbWSIYZnSoWBSUm+yNMZTIzUUhrbCcOyaT3WbpVnF/StT5weq1zQ7dRh2zHLFek8vSVfIRf9OoztgBZTIoZU=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
I've been struggling with this problem for a few days now perhaps
someone here has had experience with this problem already.  I am
trying to set up a rack server lke this:

dom0: iptables/dhcp
dom1: LAMP server
dom2: MAIL server
dom3: VNC vm for graphical admin and web tools

Dom0 has one physical interface eth0 which receives a static ip, i
have also set up a bridge called br0 that i have bound dnsmasq to in
order to dole out ips to the domU's.  The domU's are assigned a mac
address and once they boot dhclient requests an ip over 192.168.0.1
which works well.  Once the domU has booted I can ping the other
domU's by ip and the br0 itself at 192.168.0.1 as well as accessing
all the servers in the domUs in my internal network.  I.e. I can hit
the webserver in dom1 from dom3.  I can also ping external sites by
domain name like google.com.  Unfortunately that is about all I can
do.  I cannot access any other form of net traffic from inside the
domU, i.e I cannot access the web or rsync.  My question is basically,
is this a problem with Xen networking or is it a problem with
iptables?  Both?

 - Rich

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-users] Has anyone successfully set up a dhcp/iptables firewall in dom0 NATing traffic from domU?, Rich Brown <=