19 messages in com.xensource.lists.xen-devel[Xen-devel] Network issues with SuSE ...
FromSent OnAttachments
Keir Fraser07 Nov 2003 08:43 
Gregory Newby07 Nov 2003 13:53 
Ian Pratt07 Nov 2003 14:03 
Gregory Newby07 Nov 2003 14:35 
Ian Pratt07 Nov 2003 14:53 
Gregory Newby07 Nov 2003 16:29 
Ian Pratt07 Nov 2003 16:36 
Gregory Newby07 Nov 2003 17:07 
Ian Pratt07 Nov 2003 17:21 
Gregory Newby07 Nov 2003 17:38 
Ian Pratt07 Nov 2003 17:57 
Gregory Newby07 Nov 2003 18:55 
Torne Wuff07 Nov 2003 20:20 
Keir Fraser08 Nov 2003 00:48 
Gregory Newby10 Nov 2003 10:48 
Ian Pratt10 Nov 2003 12:32 
Gregory Newby10 Nov 2003 15:09 
Ian Pratt10 Nov 2003 15:25 
Torne Wuff10 Nov 2003 16:55 
Subject:[Xen-devel] Network issues with SuSE firewall
From:Gregory Newby (new@arsc.edu)
Date:11/07/2003 01:53:02 PM
List:com.xensource.lists.xen-devel

First, I noted that xen_nat_enable was *not* built along with the other tools in xeno-clone/install/bin. Is this still needed (per the README.CD instructions, for a NAT-based virtual host, rather than IP-based)?

I copied & ran the xen_nat_enable from the CD, and immediately was unable to access my machine to/from the network (I had already run "ifconfig eth0:0 169.254.1.0 up").

What I found was that the SuSEfirewall default configuration did not get along well with whatever changes to iptables were made by xen_nat_enable. My solution, which needs to be tuned later, was to edit /etc/sysconfig/SuSEfirewall2 to greatly loosen the firewall. I then restarted it:

/etc/rc.d/SuSEfirewall2_init restart /etc/rc.d/SuSEfirewall2_setup restart /etc/rc.d/SuSEfirewall2_final restart

The changes I made (again, these are certainly TOO MANY changes, but as you'll see in my next note there are still problems with network access to the virtual systems):

127c127 < FW_DEV_INT="eth0:0"

---

FW_DEV_INT=""

164c164 < FW_ROUTE="yes"

---

FW_ROUTE="no"

179c179 < FW_MASQUERADE="yes"

---

FW_MASQUERADE="no"

201c201 < FW_MASQ_NETS="169.254.1.0"

---

FW_MASQ_NETS=""

217c217 < FW_PROTECT_FROM_INTERNAL="no"

---

FW_PROTECT_FROM_INTERNAL="yes"

254c254 < FW_SERVICES_EXT_TCP="2200:2300 2049 http ssh rsync ftp smtp"

---

FW_SERVICES_EXT_TCP="2049 http ssh"

Of course, your firewall configuration might be different. -- Greg

------------------------------------------------------- This SF.Net email sponsored by: ApacheCon 2003, 16-19 November in Las Vegas. Learn firsthand the latest developments in Apache, PHP, Perl, XML, Java, MySQL, WebDAV, and more! http://www.apachecon.com/