Re: [vserver] netfilter connection tracking

From: Christoph Pleger <christoph.pleger_at_cs.uni-dortmund.de>
Date: Fri 20 Apr 2018 - 13:06:20 BST
Message-ID: <28dd67300c9e94f84836c2cf11c3923c@cs.uni-dortmund.de>

Hello,

> If there are userspace processes involved, you might want
> to try to simply give all capabilities to a guest just to
> verify, in which case there will be no restrictions compared
> to the host.

Is it possible to change an entry in /proc inside a vserver? Or even
better, set it only once at vserver start? Probably the problem is that,
because of my kernel and nftables versions, I have to enable automatic
connection tracking helpers by 'echo 1 >
/proc/sys/net/nethelper/nf_conntrack_helper' and the vservers do not
have the same value in that file as the real host.

Regards
   Christoph
Received on Fri Apr 20 13:01:37 2018

[Next/Previous Months] [Main vserver Project Homepage] [Howto Subscribe/Unsubscribe] [Paul Sladen's vserver stuff]
Generated on Fri 20 Apr 2018 - 13:01:37 BST by hypermail 2.1.8