Re: [libvirt-users] netfilter+libvirt=(smth got broken?)

2013-03-26 Thread Pablo Neira Ayuso
On Fri, Mar 22, 2013 at 02:10:33PM -0400, Laine Stump wrote: > On 03/22/2013 06:53 AM, Pablo Neira Ayuso wrote: > > On Thu, Mar 21, 2013 at 10:55:42AM +0100, Pablo Neira Ayuso wrote: > >> Hi Eric, > >> > >> On Wed, Mar 20, 2013 at 09:18:21PM -0600, Eric Blake wr

Re: [libvirt-users] netfilter+libvirt=(smth got broken?)

2013-03-22 Thread Pablo Neira Ayuso
On Thu, Mar 21, 2013 at 10:55:42AM +0100, Pablo Neira Ayuso wrote: > Hi Eric, > > On Wed, Mar 20, 2013 at 09:18:21PM -0600, Eric Blake wrote: > [...] > > > By looking at the changes you made: > > > > > >> --A FI-vnet0 -p tcp -m tcp --sport 110 -m

Re: [libvirt-users] netfilter+libvirt=(smth got broken?)

2013-03-21 Thread Pablo Neira Ayuso
Hi Eric, On Wed, Mar 20, 2013 at 09:18:21PM -0600, Eric Blake wrote: [...] > > By looking at the changes you made: > > > >> --A FI-vnet0 -p tcp -m tcp --sport 110 -m conntrack --ctstate > >> ESTABLISHED -m conntrack --ctdir ORIGINAL -j RETURN > >> +-A FI-vnet0 -p tcp -m tcp --sport 110 -m conntra

Re: [libvirt-users] netfilter+libvirt=(smth got broken?)

2013-03-20 Thread Pablo Neira Ayuso
Hi Nikolai, On Wed, Mar 20, 2013 at 05:41:37PM +0400, Nikolai Zhubr wrote: > Hello, > 20.03.2013 16:47, I wrote: > [...] > >This all looks to me as if "--ctdir" argument somehow magically changed > >its meaning to the opposite, but this just cannot be! I'm out of ideas > >and looking for insights.