Editing Setting up an iptables firewall

Jump to: navigation, search

Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.

The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision Your text
Line 5: Line 5:
 
The scripts and pathnames given here are for Fedora Core 6, though they can probably be applied to most similar SysV-like systems with little modification.
 
The scripts and pathnames given here are for Fedora Core 6, though they can probably be applied to most similar SysV-like systems with little modification.
  
== A little background ==
+
Writing has enabled me to help others bring forth their own desire to self-advocate for the Earth. , <a href="http//members.multimania.co.uk/twisnetranews/texmexbeachbabesyucatan02.mov.html">texmexbeachbabesyucatan02.mov</a>, [url="http//members.multimania.co.uk/twisnetranews/texmexbeachbabesyucatan02.mov.html"]texmexbeachbabesyucatan02.mov[/url], http//members.multimania.co.uk/twisnetranews/texmexbeachbabesyucatan02.mov.html texmexbeachbabesyucatan02.mov,  lvq,
 
 
On our systems, we use the HN to provide privileged services which are not appropriate for access by the containers. For example, the HN acts as a backup server, runs Nagios for health monitoring, has a webserver for managing the 3ware RAID controller, etc. The containers are leased to customers, who can't entirely be trusted, especially if they get hacked. As such, our scenario is one in which the HN must be protected from all access (even from the containers) except for a few trusted hosts (e.g. my home-office).
 
 
 
The exception to this is the nameserver, which we want open to the world. We use it as a caching nameserver for our containers and also to host DNS for a few customer domain.
 
  
 
== Simple firewall configuration independent of IP addresses: vzfirewall ==
 
== Simple firewall configuration independent of IP addresses: vzfirewall ==

Please note that all contributions to OpenVZ Virtuozzo Containers Wiki may be edited, altered, or removed by other contributors. If you don't want your writing to be edited mercilessly, then don't submit it here.
If you are going to add external links to an article, read the External links policy first!

To edit this page, please answer the question that appears below (more info):

Cancel Editing help (opens in new window)