Re: [Libvir] iptables masquerade rule overexpansive

2008-03-27 Thread Daniel P. Berrange
On Thu, Mar 27, 2008 at 01:23:25PM -0500, Charles Duffy wrote: > On my system, libvirt-0.4.0-2ubuntu6 added the following rule to allow > my virtual hosts NATted access to the outside world: > > >Chain POSTROUTING (policy ACCEPT 33904 packets, 2146K bytes) > > pkts bytes target prot opt in

[Libvir] iptables masquerade rule overexpansive

2008-03-27 Thread Charles Duffy
On my system, libvirt-0.4.0-2ubuntu6 added the following rule to allow my virtual hosts NATted access to the outside world: Chain POSTROUTING (policy ACCEPT 33904 packets, 2146K bytes) pkts bytes target prot opt in out source destination 779 102K MASQUERADE all -