Jeppe,

What type of filtering capabilities do you need? We're currently working on this:

http://arc.opensolaris.org/caselog/PSARC/2009/436/inception.materials/link_protect.txt

You can configure these properties on the VNICs themselves transparently to the non-global zones without the need to go through ip.

Nicolas.

Jeppe Toustrup wrote:
Hi, thank for the reply.

You are right, I would like to have a firewall outside of the zones. It's too 
bad it doesn't exist yet, since I then would have to set the server up as a 
router for the zones on it, in order to have the packages pass through IP 
Filter, by which I lose the transparency.

Oh well, you can't have it all, can you? :)

/Jeppe
_______________________________________________
networking-discuss mailing list
[email protected]

Reply via email to