[libvirt-users] macvtap direct and ip spoofing

vlad halilov vlad.halilov at gmail.com
Tue Nov 19 11:12:16 UTC 2013


That's bad. So, no way to protect network from vm's ip spoofing using
macvtap?

On Tue, Nov 19, 2013 at 2:21 PM, Laine Stump <laine at laine.org> wrote:

>
> The kernel macvtap packet processing bypasses both iptables and
> ebtables, so libvirt's filters are ineffective for guest interfaces
> using a macvtap connection.
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/libvirt-users/attachments/20131119/5d979a59/attachment.htm>


More information about the libvirt-users mailing list