[Vserver] Routing in VServers

2007-02-14 Thread Asier Baranguán
Hi all! Networking firewall are not my strong points, so perhaps this could sound a silly question. I've five linux VServers, each with it's own _real_ IP address (not 192.168.x.y, 10.x, etc). Each one has it's own services but I'd like to close access from outside to some ports, but allow

Re: [Vserver] Routing in VServers

2007-02-14 Thread Oliver Welter
Hi Asier, Networking firewall are not my strong points, so perhaps this could sound a silly question. There are only silly answers... I've five linux VServers, each with it's own _real_ IP address (not 192.168.x.y, 10.x, etc). Each one has it's own services but I'd like to close access

Re: [Vserver] Routing in VServers

2007-02-14 Thread Christian Affolter
Hi! I've five linux VServers, each with it's own _real_ IP address (not 192.168.x.y, 10.x, etc). Those are real too ;) Just not supposed to be routed on the public Internet. Each one has it's own services but I'd like to close access from outside to some ports, but allow full communication

Re: [Vserver] Compiling 2.6.19.1 with vs+grsec

2007-02-14 Thread harry
i will fix this monday! it will also contain grsec 2.1.10 which is released today and it will be for 2.6.19.2 ;) 2 more days... ;) grtz, Johan Marcusson wrote: Hi I just tried compiling kernel 2.6.19.1 patched with vs2.2.0-rc6-grsec2.1.9 (latest upcoming stable). I doesn't seem to work

Re: [Vserver] Compiling 2.6.19.1 with vs+grsec

2007-02-14 Thread harry
i couldn't wait... it's done the patch is fixed (the struct was removed one way or another :S) btw. do you really need legacy stuff? ;) grtz, Johan Marcusson wrote: Hi I just tried compiling kernel 2.6.19.1 patched with vs2.2.0-rc6-grsec2.1.9 (latest upcoming stable). I doesn't seem to work

Re: [Vserver] Routing in VServers

2007-02-14 Thread harry
heya, i don't think this is what you're looking for, but i put my firewalling and routing scripts (pre-start and post-stop) online : http://people.linux-vserver.org/~harry/scripts/ hope you find some use in it... greetz, Asier Baranguán wrote: Hi all! Networking firewall are not my

Re: [Vserver] Routing in VServers

2007-02-14 Thread Bruno
On Wednesday 14 February 2007 17:17:39 Oliver Welter wrote: Hi Asier, Networking firewall are not my strong points, so perhaps this could sound a silly question. There are only silly answers... I've five linux VServers, each with it's own _real_ IP address (not 192.168.x.y, 10.x,

Re: [Vserver] Network - How is it implemented?

2007-02-14 Thread Herbert Poetzl
On Tue, Feb 13, 2007 at 02:55:58PM +0100, Jaroslav Tomecek wrote: Hi, I'm writing some comparison of kernel-based virtualization machines. I want to know something about Linux-VServer networking. I found something (is it true?): 1) There is no virtual network device. correct,

Re: [Vserver] Routing in VServers

2007-02-14 Thread Herbert Poetzl
On Wed, Feb 14, 2007 at 05:17:39PM +0100, Oliver Welter wrote: Hi Asier, Networking firewall are not my strong points, so perhaps this could sound a silly question. There are only silly answers... I've five linux VServers, each with it's own _real_ IP address (not 192.168.x.y,

Re: [Vserver] Routing in VServers

2007-02-14 Thread Oliver Welter
Hi Bruno, Sorry Oliver, but local traffic DOES cross iptables (INPUT and OUTPUT rules, not sure about pre/post-routing), but crossing is done with interface 'lo' instead of 'eth*' or whatever other interface. sorry you are totally right - fingers were faster then neurons :( Oliver --