T tincboy Renowned Member Apr 13, 2010 466 4 83 Jul 10, 2012 #1 I need to block an outgoing port of xxxx from one of my VMs (KVM one), Any experience on this job?
T tincboy Renowned Member Apr 13, 2010 466 4 83 Jul 10, 2012 #3 In proxmox 1.9, I simply add a drop rule in forward table and it was fine, But in Proxmox 2 no success with this trend.
In proxmox 1.9, I simply add a drop rule in forward table and it was fine, But in Proxmox 2 no success with this trend.
T tincboy Renowned Member Apr 13, 2010 466 4 83 Jul 10, 2012 #4 Any suggestion on why iptables rules are to working on VMs any more?
dietmar Proxmox Staff Member Staff member Apr 28, 2005 17,256 654 213 Austria www.proxmox.com Jul 11, 2012 #5 Not sure, but maybe related to new settings in /etc/sysctl.d/pve.conf
T tincboy Renowned Member Apr 13, 2010 466 4 83 Jul 11, 2012 #6 dietmar said: Not sure, but maybe related to new settings in /etc/sysctl.d/pve.conf Click to expand... I guess you are right, look at the link below: http://www.linuxplayer.org/2011/04/rhel6-disabled-iptables-on-bridge-interface-by-default Right now I have no free server to test this settings but I will test in 1 or 2 days.
dietmar said: Not sure, but maybe related to new settings in /etc/sysctl.d/pve.conf Click to expand... I guess you are right, look at the link below: http://www.linuxplayer.org/2011/04/rhel6-disabled-iptables-on-bridge-interface-by-default Right now I have no free server to test this settings but I will test in 1 or 2 days.
T tincboy Renowned Member Apr 13, 2010 466 4 83 Sep 2, 2012 #7 I've test it on many servers and it seems the issue will be gone if you enable these options in /etc/sysctl.d/pve.conf Code: net.bridge.bridge-nf-call-iptables = 1 net.bridge.bridge-nf-call-arptables = 1 and then restart the service below: Code: sysctl -p /etc/init.d/procps restart
I've test it on many servers and it seems the issue will be gone if you enable these options in /etc/sysctl.d/pve.conf Code: net.bridge.bridge-nf-call-iptables = 1 net.bridge.bridge-nf-call-arptables = 1 and then restart the service below: Code: sysctl -p /etc/init.d/procps restart