36
edits
Changes
no edit summary
For input packets context switching is inherited from the routing entry, for output - inherited from the socket one.
=== Socket virtualization isolation (Linux-VServer) ===
'''Requirements''':
# all interfaces and IPs are visible on the host
# routing and iptables is configured on the host
| 3d level virtualization || - || i || i || i || -
|-
| bind filtering sockets isolation || - || - || i || - || -|-| network isolation || i/m || i || i || i/m || -
|}
* 'v' - virtualized
* 'i' - isolated
* '-' - neither virtualized nor isolated
[[Category:Containers]]