I've not looked at this *at all*, but one thought is to have a
eucalyptus chain (or chains) that eucalyptus manages. It can add the
chain on boot, and then add rules to the chain. Then it can manage the
chain however it wants (even flush it). Once added, the chain is never
removed from the BUILTIN
and by depended on across reboots and flushes I meant depended on
across reboots and eucalyptus flushes.
--
very hard to firewall eucalyptus securely
https://bugs.launchpad.net/bugs/412664
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to
Confirming, marking wishlist.
It might be worth having a session at UDS on this topic, as it sounds
like it would take input from a number of people.
:-Dustin
** Changed in: eucalyptus (Ubuntu)
Status: New = Confirmed
** Changed in: eucalyptus (Ubuntu)
Importance: Undecided =