Re: [libvirt] [PATCH 4/9] add DHCP snooping support to nwfilter

2011-05-11 Thread Stefan Berger
David Stevens/Beaverton/IBM@IBMUS wrote on 05/09/2011 04:06:29 PM: This patch simplifies the table rules by setting the protocol chainspolicy to be DROP and removes the explicit -j DROP entries that the protocol rules had previously. It also makes no-other-rarp-traffic.xml obsolete.

Re: [libvirt] [PATCH 4/9] add DHCP snooping support to nwfilter

2011-05-11 Thread David Stevens
Stefan Berger/Watson/IBM wrote on 05/11/2011 12:32:41 PM: So now this command puts the default policy of every ebtables chain to end with an implicit drop. What if I had previously created a filter assuming an implicit accept, which is the current behavior? Now that filter wouldn't work

[libvirt] [PATCH 4/9] add DHCP snooping support to nwfilter

2011-05-09 Thread David L Stevens
This patch simplifies the table rules by setting the protocol chains policy to be DROP and removes the explicit -j DROP entries that the protocol rules had previously. It also makes no-other-rarp-traffic.xml obsolete. Signed-off-by: David L Stevens dlstev...@us.ibm.com diff --git

[libvirt] [PATCH 4/9] add DHCP snooping support to nwfilter

2011-05-09 Thread David L Stevens
This patch simplifies the table rules by setting the protocol chains policy to be DROP and removes the explicit -j DROP entries that the protocol rules had previously. It also makes no-other-rarp-traffic.xml obsolete. Signed-off-by: David L Stevens dlstev...@us.ibm.com diff --git