Re: Shorewall and libvirt

2021-05-07 Thread Andrei POPESCU
On Jo, 06 mai 21, 17:18:26, Charles Curley wrote: > > I will. I believe the Powers That Be at Debian prefer one file a bug > report with Debian, and the Debian maintainers will file an upstream > bug if necessary. Anyway, that's the course I plan to take. Do feel free to file bugs directly with

Re: Shorewall and libvirt

2021-05-06 Thread Charles Curley
On Thu, 6 May 2021 21:25:44 +0200 john doe wrote: > > I missed it. Sorry. > > > > It is hard to spot it, I was simply mentioning it to let you validate > what I was saying and not to put you on the spot! No worries. I did not take it as putting me on the spot. > > >> > >> > >> Remember

Re: Shorewall and libvirt

2021-05-06 Thread john doe
On 5/6/2021 8:13 PM, Charles Curley wrote: On Thu, 6 May 2021 09:49:29 +0200 john doe wrote: First you need to disable libvirt from playing with iptables, I changed (virsh net-edit default) from: to: Thank you, that seems to have worked. Then you can use whatever firewalling

Re: Shorewall and libvirt

2021-05-06 Thread Charles Curley
On Thu, 6 May 2021 09:49:29 +0200 john doe wrote: > First you need to disable libvirt from playing with iptables, I > changed (virsh net-edit default) from: > > > to: > > Thank you, that seems to have worked. > > Then you can use whatever firewalling solution you like (this is >

Re: Shorewall and libvirt

2021-05-06 Thread john doe
On 5/6/2021 5:03 AM, Charles Curley wrote: For years, up through Buster, I have had a nice setup with virtual machines on my laptops, with firewalling provided by shorewall and rules I have added over the years. As I move from network to network, the firewall is reconfigured, and the VMs

Shorewall and libvirt

2021-05-05 Thread Charles Curley
For years, up through Buster, I have had a nice setup with virtual machines on my laptops, with firewalling provided by shorewall and rules I have added over the years. As I move from network to network, the firewall is reconfigured, and the VMs continue to work. I also have scripts that detect my