All of lore.kernel.org
 help / color / mirror / Atom feed
* Bridges
@ 2010-08-17 22:44 Jonathan Tripathy
  2010-08-17 22:56 ` Bridges Jan Engelhardt
                   ` (2 more replies)
  0 siblings, 3 replies; 72+ messages in thread
From: Jonathan Tripathy @ 2010-08-17 22:44 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

When using a single Linux host with lots of bridges, would there ever be 
a time, even for a few seconds, where traffic would "jump" bridges?

I know a previous poster mentioned that when adding a host to a bridge, 
for a few seconds all packets get sent everywhere, however does this 
only apply to the bridge that the new host was added to, or all bridges 
in the system?

Reason I ask is that I am considering have one bridge for public traffic 
and one bridge for private, and don't want private traffic to be seen by 
hosts connected to the public bridge.

Thanks

^ permalink raw reply	[flat|nested] 72+ messages in thread
* bridges
@ 2009-05-07 15:57 Ross Boylan
       [not found] ` <4A03169C.60301@cs.ualberta.ca>
  2009-05-07 21:15 ` bridges Matthew Palmer
  0 siblings, 2 replies; 72+ messages in thread
From: Ross Boylan @ 2009-05-07 15:57 UTC (permalink / raw)
  To: kvm; +Cc: ross

I'm trying to understand bridging with KVM, but am still puzzled.
I think that the recommended bridging with TAP means that packets from
the VM will end up going out the host card attached to the default
gateway.  But it looks to me as if their IP address is unchanged, which
means replies will never reach me.  Is that correct?  Do I need to NAT
the packets, or is something already doing that?

Some documents indicate that I need to bring the interfaces (e.g., eth0)
down before I bring the bridge up, and that afterwards only the bridge
will have an IP address.  Is that right?

Some documents, e.g.,
http://ebtables.sourceforge.net/br_fw_ia/br_fw_ia.html, indicate
iptables should "just work" with bridging.  However, I've seen someone
with a 2.6.15 kernel ask about firewalling and be told they needed to
patch the kernel to get it work (don't have the reference handy).
Should it just work?

I'm running a 2.6.29 kernel on Debian Lenny with kvm 72+dfsg-5~lenny1.
Version 84+dfsg-2 is available in experimental.  Is there much to be
gained by going with the more recent version?

Please cc me; I'm not on the list.

Thanks.
Ross Boylan



^ permalink raw reply	[flat|nested] 72+ messages in thread

end of thread, other threads:[~2010-08-24 22:20 UTC | newest]

Thread overview: 72+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-08-17 22:44 Bridges Jonathan Tripathy
2010-08-17 22:56 ` Bridges Jan Engelhardt
2010-08-17 23:34   ` Bridges Stephen Hemminger
2010-08-18 11:27 ` Bridges Thomas Jacob
2010-08-18 19:51   ` Bridges Jonathan Tripathy
2010-08-18 21:51 ` Bridges Grant Taylor
2010-08-18 21:57   ` Bridges Jonathan Tripathy
2010-08-18 22:08     ` Bridges Grant Taylor
2010-08-18 22:15       ` Bridges Jonathan Tripathy
2010-08-18 22:26         ` Bridges Jan Engelhardt
2010-08-18 22:51           ` Bridges Jonathan Tripathy
2010-08-18 23:05             ` Bridges Pascal Hambourg
2010-08-18 23:07               ` Bridges Jonathan Tripathy
2010-08-18 23:21                 ` Bridges Pascal Hambourg
2010-08-18 23:23                   ` Bridges Jonathan Tripathy
2010-08-18 23:45                   ` Bridges Jonathan Tripathy
2010-08-19  7:26                     ` Bridges Pascal Hambourg
2010-08-19 18:47                       ` Bridges Jonathan Tripathy
2010-08-19 19:26                         ` Bridges Pascal Hambourg
2010-08-19 19:37                           ` Bridges Jonathan Tripathy
2010-08-19 20:00                             ` Bridges Jan Engelhardt
2010-08-19 20:11                               ` Bridges Jonathan Tripathy
2010-08-19 21:14                             ` Bridges Pascal Hambourg
2010-08-19 21:24                               ` Bridges Jonathan Tripathy
2010-08-19 22:04                                 ` Bridges Pascal Hambourg
2010-08-19 22:53                                   ` Bridges Jonathan Tripathy
2010-08-20  8:53                                     ` Bridges Pascal Hambourg
2010-08-21 21:46                                       ` Bridges Jonathan Tripathy
2010-08-21 23:25                                         ` Bridges Jan Engelhardt
     [not found]                                           ` <4C70E853.6050107@abpni.co   .uk>
2010-08-22  9:05                                           ` Bridges Jonathan Tripathy
2010-08-22  9:09                                             ` Bridges Jan Engelhardt
     [not found]                                               ` <4C70E 9A2.3040907@abpni.co.uk>
2010-08-22  9:10                                               ` Bridges Jonathan Tripathy
2010-08-22 21:02                                                 ` Bridges Pascal Hambourg
     [not found]                                                   ` <4C7194 D3.7070803@abpni.co.uk>
2010-08-22 21:21                                                   ` Bridges Jonathan Tripathy
2010-08-23  8:22                                                     ` Bridges Pascal Hambourg
2010-08-23 20:18                                                       ` Bridges Jonathan Tripathy
2010-08-24  8:57                                                         ` Bridges Karel Rericha
2010-08-24 14:44                                                         ` Bridges Pascal Hambourg
2010-08-24 17:37                                                           ` Bridges Jonathan Tripathy
2010-08-24 18:07                                                             ` Bridges Pascal Hambourg
2010-08-24 18:34                                                               ` Bridges Jonathan Tripathy
2010-08-24 22:20                                                                 ` Bridges Pascal Hambourg
2010-08-20  8:38                                   ` Bridges Jan Engelhardt
2010-08-20  9:05                                     ` Bridges Pascal Hambourg
2010-08-20  9:09                                       ` Bridges Jan Engelhardt
2010-08-20 10:26                                         ` Bridges Pascal Hambourg
2010-08-20 16:02                                           ` Bridges Grant Taylor
2010-08-20 16:18                                             ` Bridges Jan Engelhardt
2010-08-20 16:25                                               ` Bridges Grant Taylor
2010-08-20 16:32                                                 ` Bridges Jan Engelhardt
2010-08-21 12:48                                             ` Bridges Pascal Hambourg
2010-08-21 21:44                                               ` Bridges Grant Taylor
2010-08-19 19:28                         ` Bridges Jan Engelhardt
2010-08-18 22:59   ` Bridges Pascal Hambourg
2010-08-18 23:00     ` Bridges Jonathan Tripathy
2010-08-18 23:11       ` Bridges Pascal Hambourg
2010-08-19  8:29       ` Bridges Jan Engelhardt
2010-08-19  9:16         ` Bridges Pascal Hambourg
2010-08-19  3:52     ` Bridges Grant Taylor
2010-08-19  7:33       ` Bridges Pascal Hambourg
2010-08-19 14:51         ` Bridges Grant Taylor
2010-08-19 14:56           ` Bridges Jan Engelhardt
2010-08-19 15:49             ` Bridges Grant Taylor
2010-08-19 16:21               ` Bridges Jan Engelhardt
2010-08-19 16:41                 ` Bridges Grant Taylor
2010-08-19 17:10                   ` Bridges Jan Engelhardt
2010-08-19 18:36                     ` Bridges Grant Taylor
2010-08-19 17:10                   ` Bridges Rick Jones
  -- strict thread matches above, loose matches on Subject: below --
2009-05-07 15:57 bridges Ross Boylan
     [not found] ` <4A03169C.60301@cs.ualberta.ca>
2009-05-07 17:48   ` bridges Ross Boylan
2009-05-07 19:19     ` bridges Cam Macdonell
2009-05-07 21:15 ` bridges Matthew Palmer

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.