All of lore.kernel.org
 help / color / mirror / Atom feed
* ipsets and network namespaces
@ 2012-04-05 11:04 Gorik Van Steenberge
  2012-04-05 11:24 ` Jozsef Kadlecsik
  0 siblings, 1 reply; 6+ messages in thread
From: Gorik Van Steenberge @ 2012-04-05 11:04 UTC (permalink / raw)
  To: netfilter-devel

Hello,

I've noticed that when creating a new network namespace (using the lxc
tools) that ipsets (userspace v6.11 on kernel 3.3.1) are still global,
i.e. an ipset created in the container is visible in the host and vice
versa. Iptables rulesets, however, are isolated.

Is this an as of yet unimplemented feature or a conscious design decision?

Thanks,
gvs

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2012-04-09 18:34 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-04-05 11:04 ipsets and network namespaces Gorik Van Steenberge
2012-04-05 11:24 ` Jozsef Kadlecsik
2012-04-08  8:17   ` Gao feng
2012-04-08 18:06     ` Jozsef Kadlecsik
2012-04-09  0:50       ` Gao feng
2012-04-09 18:34         ` Jozsef Kadlecsik

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.