Re: [CentOS] hosted VMs, VLANs, and firewalld

2016-03-21 Thread Gordon Messmer
On 03/21/2016 10:18 PM, Devin Reade wrote: However, in this case the host won't have addresses on (based on my above correction) either br2 or br3. It does sound, though, like having enp1so, enp1s0.2, and enpe1s0.3 in the 'DMZ' zone means that filtering rules on the host will affect inbound traf

Re: [CentOS] hosted VMs, VLANs, and firewalld

2016-03-21 Thread Devin Reade
--On Monday, March 21, 2016 08:57:59 AM -0700 Gordon Messmer wrote: > On 03/20/2016 08:51 PM, Devin Reade wrote: >> In a CentOS 7 test HA cluster I'm building I want both traditional >> services running on the cluster and VMs running on both nodes > > On a purely subjective note: I think that's

Re: [CentOS] hosted VMs, VLANs, and firewalld

2016-03-21 Thread Dennis Jacobfeuerborn
On 21.03.2016 16:57, Gordon Messmer wrote: > On 03/20/2016 08:51 PM, Devin Reade wrote: >> In a CentOS 7 test HA cluster I'm building I want both traditional >> services running on the cluster and VMs running on both nodes > > On a purely subjective note: I think that's a bad design. One of the >

Re: [CentOS] hosted VMs, VLANs, and firewalld

2016-03-21 Thread Gordon Messmer
On 03/20/2016 08:51 PM, Devin Reade wrote: In a CentOS 7 test HA cluster I'm building I want both traditional services running on the cluster and VMs running on both nodes On a purely subjective note: I think that's a bad design. One of the primary benefits of virtualization and other contain

[CentOS] hosted VMs, VLANs, and firewalld

2016-03-20 Thread Devin Reade
I'm looking for some information regarding the interaction of KVM, VLANs, firewalld, and the kernel's forwarding configuration. I would appreciate input especially from anyone already running a similar configuration in production. In short, I'm trying to figure out if a current configuration is