Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-15 Thread Thomas Woerner
Daniel P. Berrange wrote: On Mon, Apr 06, 2009 at 02:36:16PM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-07 Thread Daniel P. Berrange
On Mon, Apr 06, 2009 at 02:36:16PM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs to use

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-07 Thread Ludwig Nussel
David Lutterkort wrote: On Mon, 2009-04-06 at 14:36 +0200, Ludwig Nussel wrote: SuSEfirewall2 does not have such a mechanism and TBH I pretty much dislike the idea of allowing applications to inject arbitrary rules. I'd prefer some higher level abstraction so it's left to the firewall to

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-06 Thread Ludwig Nussel
Daniel P. Berrange wrote: On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs to use isolated rather than default, but rules keep being added to iptables

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-06 Thread David Lutterkort
On Mon, 2009-04-06 at 14:36 +0200, Ludwig Nussel wrote: SuSEfirewall2 does not have such a mechanism and TBH I pretty much dislike the idea of allowing applications to inject arbitrary rules. I'd prefer some higher level abstraction so it's left to the firewall to decide how to translate the

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-02 Thread Ludwig Nussel
Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs to use isolated rather than default, but rules keep being added to iptables when libvirt-bin is started. Is there a way to convince libvirt not to add these rules? No,

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-02 Thread Daniel P. Berrange
On Thu, Apr 02, 2009 at 10:16:13AM +0200, Ludwig Nussel wrote: Daniel P. Berrange wrote: On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: [...] I modified my VMs to use isolated rather than default, but rules keep being added to iptables when libvirt-bin is started.

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-01 Thread Mariano Absatz
I'm sorry... is this not the right place to ask this kind of questions? Is there another more user-oriented list or forum? TIA On Tue, Mar 31, 2009 at 16:08, Mariano Absatz el.b...@gmail.com wrote: Hi, I'm new to libvirt but not a complete neophite. I'm using libvirt and kvm in ubuntu with

Re: [libvirt] How to prevent libvirt from adding iptables rules?

2009-04-01 Thread Daniel P. Berrange
On Tue, Mar 31, 2009 at 04:08:24PM -0300, Mariano Absatz wrote: At first I used the 'default' network (with a different rfc1918 network)... everything was kinda working until I rebooted the host... at that point I lost connectivity between the outside world and the VMs. From inside the host