Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-15 Thread Thomas Woerner
Daniel P. Berrange wrote: On Mon, Apr 06, 2009 at 02:36:16PM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-07 Thread Ludwig Nussel
David Lutterkort wrote: > On Mon, 2009-04-06 at 14:36 +0200, Ludwig Nussel wrote: > > SuSEfirewall2 does not have such a mechanism and TBH I pretty much > > dislike the idea of allowing applications to inject arbitrary rules. > > I'd prefer some higher level abstraction so it's left to the > > fire

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-07 Thread Ludwig Nussel
Daniel P. Berrange wrote: > On Mon, Apr 06, 2009 at 02:36:16PM +0200, Ludwig Nussel wrote: > > Daniel P. Berrange wrote: > > > On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: > > > > Daniel P. Berrange wrote: > > > > > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: >

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-07 Thread Daniel P. Berrange
On Mon, Apr 06, 2009 at 02:36:16PM +0200, Ludwig Nussel wrote: > Daniel P. Berrange wrote: > > On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: > > > Daniel P. Berrange wrote: > > > > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > > > > > [...] > > > > > I modified

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-06 Thread David Lutterkort
On Mon, 2009-04-06 at 14:36 +0200, Ludwig Nussel wrote: > SuSEfirewall2 does not have such a mechanism and TBH I pretty much > dislike the idea of allowing applications to inject arbitrary rules. > I'd prefer some higher level abstraction so it's left to the > firewall to decide how to translate th

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-06 Thread Ludwig Nussel
Daniel P. Berrange wrote: > On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: > > Daniel P. Berrange wrote: > > > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > > > > [...] > > > > I modified my VMs to use isolated rather than default, but rules keep > > > > being a

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-02 Thread Mariano Absatz
(sorry, Daniel... I had only answered you instead of copying the list also) Daniel P. Berrange escribió el 01/04/09 09:41: > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > >> At first I used the 'default' network (with a different rfc1918 >> network)... everything was kinda

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-02 Thread Daniel P. Berrange
On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: > Daniel P. Berrange wrote: > > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > > > [...] > > > I modified my VMs to use isolated rather than default, but rules keep > > > being added to iptables when libvirt-bin is s

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-02 Thread Ludwig Nussel
Daniel P. Berrange wrote: > On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > > [...] > > I modified my VMs to use isolated rather than default, but rules keep > > being added to iptables when libvirt-bin is started. > > > > Is there a way to convince libvirt not to add these rule

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-01 Thread Daniel P. Berrange
On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: > At first I used the 'default' network (with a different rfc1918 > network)... everything was kinda working until I rebooted the host... at > that point I lost connectivity between the outside world and the VMs. > From inside the h

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-01 Thread Mariano Absatz
I'm sorry... is this not the right place to ask this kind of questions? Is there another more user-oriented list or forum? TIA On Tue, Mar 31, 2009 at 16:08, Mariano Absatz wrote: > Hi, > > I'm new to libvirt but not a complete neophite. > > I'm using libvirt and kvm in ubuntu with "vmbuilder".