Re: [ovs-discuss] ovs + iptables + xcp

2012-07-27 Thread pf shineyear
ye~, it's true , i already tried, it's not work at all~~, but thanks for your help. i just found something in openvswitch document http://openvswitch.org/openstack/documentation/ at the last section , they said OVS is not compatible with iptables + ebtables rules that are applied directly on VI

Re: [ovs-discuss] ovs + iptables + xcp

2012-07-26 Thread Jesse Gross
On Thu, Jul 26, 2012 at 12:40 PM, Luiz Ozaki wrote: > On 7/25/12 8:07 PM, pf shineyear wrote: > > > i just want to use ovs + iptables to limit all the input access, like drop > all request to ip 10.1.0.3 , but only accept all request send from vm, like > wget www.google.com. > > i already use ovs-

Re: [ovs-discuss] ovs + iptables + xcp

2012-07-26 Thread Luiz Ozaki
On 7/25/12 8:07 PM, pf shineyear wrote: i just want to use ovs + iptables to limit all the input access, like drop all request to ip 10.1.0.3 , but only accept all request send from vm, like wget www.google.com . i already use ovs-ofctl to drop all input access from ou

Re: [ovs-discuss] ovs + iptables + xcp

2012-07-25 Thread pf shineyear
thanks for your reply jesse, my question is , i just want to use ovs + iptables to limit all the input access, like drop all request to ip 10.1.0.3 , but only accept all request send from vm, like wget www.google.com. i already use ovs-ofctl to drop all input access from outside, like dl_type=0x

Re: [ovs-discuss] ovs + iptables + xcp

2012-07-25 Thread Jesse Gross
On Tue, Jul 24, 2012 at 5:59 PM, pf shineyear wrote: > hi all , > > i have a big problem with ovs + iptables + xcp in ubuntu 12.04 > > i can limit every request input on xenbr1, but i can not do like iptables > established filter for the vm output, > > when a vm send a request output , i can see i

[ovs-discuss] ovs + iptables + xcp

2012-07-25 Thread pf shineyear
hi all , i have a big problem with ovs + iptables + xcp in ubuntu 12.04 i can limit every request input on xenbr1, but i can not do like iptables established filter for the vm output, when a vm send a request output , i can see it success to go out , and in eth1, i can see the response come back