В Срд, 28.04.2004, в 09:14, Alexander Denisov пишет:
> В сообщении от 27 Апрель 2004 18:02 Herbert Poetzl написал(a):
> > > Can i use iptables rules in ctx ?
> >
> > yes, there are two alternatives:
> >
> >  - allow the vserver to modify _all_ iptable rules
> 
> Where i can read how to allow ? 
Add CAP_NETADMIN capability to you vserver :) but it allow all network
operations from this vserver with all network objects, as routing, ip
address and all other..

> Can i allow one vserver or all vservers?
Who have CAP_NETADMIN capability - can work with iptables and other
network objects.


> Can i allow vserver to modify one chain ?
you can`t do it. 
-- 
Alex Lyashkov <[EMAIL PROTECTED]>
PSoft
_______________________________________________
Vserver mailing list
[EMAIL PROTECTED]
http://list.linux-vserver.org/mailman/listinfo/vserver

Reply via email to