Re: [libvirt-users] The firewall just doesn't make any sense

2013-07-15 Thread Sven Schwedas
On 15.07.2013 12:57, Daniel P. Berrange wrote: > On Mon, Jul 15, 2013 at 12:52:20PM +0200, Sven Schwedas wrote: >> Could *somebody* shed some light on how the firewall is supposed to >> work? I haven't even managed to get trivial firewall rules to work. As >> mentioned, the examples in the document

Re: [libvirt-users] The firewall just doesn't make any sense

2013-07-15 Thread Daniel P. Berrange
On Mon, Jul 15, 2013 at 12:52:20PM +0200, Sven Schwedas wrote: > Could *somebody* shed some light on how the firewall is supposed to > work? I haven't even managed to get trivial firewall rules to work. As > mentioned, the examples in the documentation generate completely > nonsensical rulesets, an

Re: [libvirt-users] The firewall just doesn't make any sense

2013-07-15 Thread Sven Schwedas
Could *somebody* shed some light on how the firewall is supposed to work? I haven't even managed to get trivial firewall rules to work. As mentioned, the examples in the documentation generate completely nonsensical rulesets, and if I try writing my own, they make even less sense. For example: >

[libvirt-users] The firewall just doesn't make any sense

2013-07-10 Thread Sven Schwedas
Okay, some more fiddling: If I try the second filterset from the second example from the documentation ( http://libvirt.org/formatnwfilter.html#nwfwriteexample2nd ), the resulting firewall rules make even less sense. To quote, what it should do: > opens only TCP ports 22 and 80 of a VM's interfac