> Is veth1 up? (Maybe you need "ifconfig veth1 up".) You shouldn't need > the iptables line unless you have other iptables stuff that might > potentially block it. And there are some emails on the web referring > to issues with iptables conntrack and veth. Well, as kind of predicted by everybody, I eventually switched to putting an IP address on br0. The reason was that when I configured tap0/eth0 in the VM then masquerading did not work correctly; the first ping from inside the VM to the internet worked, but then immediately it stopped. I did some googling and it seemed not an uncommon problem, but a quick test of putting an IP on br0 immediately solved the problem. Thanks again for the all the very good and speedy advice I was given! Alexis _______________________________________________ Bridge mailing list Bridge@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linux-foundation.org/mailman/listinfo/bridge