Re: LXC, networking and firewalling

2019-05-15 Thread Reco
Hi. On Thu, May 16, 2019 at 01:28:41PM +1200, Richard Hector wrote: > Hi all, > What I think doesn't work so well is attempting to filter traffic either > between containers, "modproble br_netfilter", then it'll be the same netfilter rules. > or between a container and the host. Should

LXC, networking and firewalling

2019-05-15 Thread Richard Hector
Hi all, I have a couple of VPSes (Xen and KVM based), in which I run LXC containers. Currently I have a bridge device set up on the host (not bridged to the external network), and iptables to do firewalling and NAT as required. Here's my bridge setup, if that helps: ---8<---