Re: interfaces in /proc/net/ip_conntrack

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Martijn Lievaart <m@xxxxxxx> writes:

> Have a look at User Mode Linux (UML). It allows to run virtual
> machines with the least overhead of all virtaul machine mechanisms I
> know. I have no idea how you have to do the plumbing to get the right
> packets to the right VM, but I think it can be done.

UML isn't particularly lightweight -- it requires a kernel per name
space. OpenVZ can virtualize machines with just one kernel, but the
conntrack tables will be separate.

(At least I believe that is true, I've used OpenVZ for virtual routers
but not for virtual firewalls.)


/Benny


-
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux