From: Gao feng <gaofeng@cn.fujitsu.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: Gorik Van Steenberge <gorik.vansteenberge@gmail.com>,
netfilter-devel@vger.kernel.org
Subject: Re: ipsets and network namespaces
Date: Sun, 08 Apr 2012 16:17:39 +0800 [thread overview]
Message-ID: <4F8149A3.1080607@cn.fujitsu.com> (raw)
In-Reply-To: <alpine.DEB.2.00.1204051324190.23192@blackhole.kfki.hu>
于 2012年04月05日 19:24, Jozsef Kadlecsik 写道:
> On Thu, 5 Apr 2012, Gorik Van Steenberge wrote:
>
>> I've noticed that when creating a new network namespace (using the lxc
>> tools) that ipsets (userspace v6.11 on kernel 3.3.1) are still global,
>> i.e. an ipset created in the container is visible in the host and vice
>> versa. Iptables rulesets, however, are isolated.
>>
>> Is this an as of yet unimplemented feature or a conscious design decision?
>
> It's an unimplemented feature - no one requested it yet ;-).
Hi Jozsef:
And I see there are a lot of /proc/sys/entries are not isolated.
is this an unimplemented feature too?
If so,I want to implement it.
How do you think about this?
>
> Best regards,
> Jozsef
> -
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2012-04-08 8:17 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-04-05 11:04 ipsets and network namespaces Gorik Van Steenberge
2012-04-05 11:24 ` Jozsef Kadlecsik
2012-04-08 8:17 ` Gao feng [this message]
2012-04-08 18:06 ` Jozsef Kadlecsik
2012-04-09 0:50 ` Gao feng
2012-04-09 18:34 ` Jozsef Kadlecsik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4F8149A3.1080607@cn.fujitsu.com \
--to=gaofeng@cn.fujitsu.com \
--cc=gorik.vansteenberge@gmail.com \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.