Re: [pve-devel] ovs 2.4 : conntrack nat presenation

2015-07-23 Thread Alexandre DERUMIER
. - Mail original - De: dietmar diet...@proxmox.com À: Dmitry Petuhov mityapetu...@gmail.com, aderumier aderum...@odiso.com Cc: pve-devel pve-devel@pve.proxmox.com Envoyé: Mercredi 22 Juillet 2015 20:10:28 Objet: Re: [pve-devel] ovs 2.4 : conntrack nat presenation but having

Re: [pve-devel] ovs 2.4 : conntrack nat presenation

2015-07-22 Thread Alexandre DERUMIER
an openvswitch openflow native implementation, could be great too. - Mail original - De: Dmitry Petuhov mityapetu...@gmail.com À: pve-devel pve-devel@pve.proxmox.com Envoyé: Mercredi 22 Juillet 2015 16:16:22 Objet: Re: [pve-devel] ovs 2.4 : conntrack nat presenation 22.07.2015 12:42, Alexandre

Re: [pve-devel] ovs 2.4 : conntrack nat presenation

2015-07-22 Thread Dietmar Maurer
but having an openvswitch openflow native implementation, could be great too. Oh, you want to implement it with openflow? Would be quite interesting to compare firewall performance (openflow vs. iptables) ... ___ pve-devel mailing list

[pve-devel] ovs 2.4 : conntrack nat presenation

2015-07-22 Thread Alexandre DERUMIER
just found this: http://openvswitch.org/support/ovscon2014/17/1030-conntrack_nat.pdf I'll try to look at this in the next months. (ovs firewall without iptables/bridge trick) ___ pve-devel mailing list pve-devel@pve.proxmox.com

Re: [pve-devel] ovs 2.4 : conntrack nat presenation

2015-07-22 Thread Dmitry Petuhov
22.07.2015 12:42, Alexandre DERUMIER пишет: just found this: http://openvswitch.org/support/ovscon2014/17/1030-conntrack_nat.pdf I'll try to look at this in the next months. (ovs firewall without iptables/bridge trick) Maybe better adopt nftables in PVE 4.0? It works on all network layers