Re: [vserver] Linux Vserver and Shorewall.

From: Sergiusz Pawlowicz <sergiusz_at_pawlowicz.name>
Date: Sun 25 Aug 2013 - 20:35:46 BST
Message-ID: <CAPRDrAFUuEa=_D_0gwWvvMey+BbiUXgSy+FF5i2hL3UPSU_PTQ@mail.gmail.com>

On Sun, Aug 25, 2013 at 8:01 PM, Adriaan
<adriaan@a-happy-linux-vserver-user.nl> wrote:
> Hi there,
>
> First of all, many thanks for Linux Vserver, and many thanks for the
> Sand repository for Debian Wheezy. Lifesavers. Great, thanks!
>
> I like to use Shorewall but can't get it to work with Linux Vserver.
> (I'm using Shorewall with OpenVZ since quite a while, but I'm slowly
> moving from OpenVZ to Linux Vserver).
>
> Scenario :
> One public ip address.
> One NIC.
> Vservers have 10.0.0.x addresses, using NAT to separate web and email
> services over various vservers.

you cannot use /etc/shorewal/nat for several vserver guests, if you
have only one IP, it is designed for 1:1 traffic. you must use
separate DNAT rules in shorewall/rules and utilize eg. shorewall/masq
for SNAT traffic

contact me on jabber (the same address as email if you want live help)

s.
Received on Sun Aug 25 20:36:35 2013

[Next/Previous Months] [Main vserver Project Homepage] [Howto Subscribe/Unsubscribe] [Paul Sladen's vserver stuff]
Generated on Sun 25 Aug 2013 - 20:36:35 BST by hypermail 2.1.8