Editing Using veth and brctl for protecting HN and saving IP addresses
Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.
The edit can be undone.
Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
− | Configuration described below has been suggested by Ugo123. | + | Configuration described below has been suggested by Ugo123. Appreciates. |
Consider we are facing the following task: | Consider we are facing the following task: | ||
− | + | 1) We have limited range of IP addresses granted by ISP. | |
− | + | We want to assign as much granted IPs to containers as possible. | |
+ | We do not want to protect containers from Internet. | ||
+ | 2) We want to protect the HN OS (CT0) from Internet and make it possible to manage containers from CT0 within local area network. | ||
− | Assume we have a | + | Assume we have a HN with 2 Ethernet cards (interfaces eth0 and eth1), OpenVZ kernel 2.6.18-028stab033, vzctl version 3.0.16, |
bridge-utils version 1.1. OpenVZ installation process is covered in [[quick installation]]. | bridge-utils version 1.1. OpenVZ installation process is covered in [[quick installation]]. | ||
− | + | Task can be effectively solved by setting up the configuration presented on Figure 1. | |
Figure 1: Effective configuration. 10.0.98.96-10.0.98.X - range of IP addresses granted by ISP, 192.168.1.136 - IP address from LAN | Figure 1: Effective configuration. 10.0.98.96-10.0.98.X - range of IP addresses granted by ISP, 192.168.1.136 - IP address from LAN | ||
Line 47: | Line 49: | ||
RX bytes:2078718 (1.9 MiB) TX bytes:2078718 (1.9 MiB) | RX bytes:2078718 (1.9 MiB) TX bytes:2078718 (1.9 MiB) | ||
</pre> | </pre> | ||
− | Let us | + | Let us pass through the setup process step by step. |
1) Create 2 containers on the HN as described in http://download.openvz.org/doc/OpenVZ-Users-Guide.pdf. | 1) Create 2 containers on the HN as described in http://download.openvz.org/doc/OpenVZ-Users-Guide.pdf. | ||
Line 212: | Line 214: | ||
If all the steps are done as written, it should work. | If all the steps are done as written, it should work. | ||
Enjoy. | Enjoy. | ||
− | |||
− | |||
− |