Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Charles Duffy <Charles_Duffy@messageone.com>
To: netfilter@vger.kernel.org
Subject: NETMAP of destination *after* routing
Date: Wed, 06 Aug 2008 17:57:42 -0500	[thread overview]
Message-ID: <g7da9g$21r$1@ger.gmane.org> (raw)

Howdy, all. I'm looking at building NETMAP-like functionality into 
libvirt, such that groups of guest VMs (each group on its own bridge) 
can think they're sharing the same address space, but be separately 
addressable from outside (including the VM host itself). This has 
applications in automated QA -- being able to suspend a group of virtual 
machines in-flight, create an arbitrary number of copy-on-write images 
of these machines (each group of copies attached via a different bridge 
device) connected to different bridges, and being immediately able to 
separately address each copy via a distinct network address without 
reconfiguration.

Unfortunately, the current behavior of NETMAP -- translating the source 
address in POSTROUTING and the destination in PREROUTING -- doesn't 
appear to work for this purpose: I still need the original destination 
intact when routing to decide which bridge packets should go out.


How do 'yall suggest resolving this? I've played around with 
xtables-addons somewhat, and am pondering building a target to do 
translation in the mangle table on a packet-by-packet basis (as my 
present understanding -- correct or otherwise -- is that translating the 
destination post-routing with existing conntrack-based NAT functionality 
simply isn't feasible)... but at present I don't know what roadblocks 
are likely to be hit in the process.

Thoughts?

Thanks!


             reply	other threads:[~2008-08-06 22:57 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-08-06 22:57 Charles Duffy [this message]
2008-08-06 23:13 ` NETMAP of destination *after* routing Jan Engelhardt
2008-08-07 19:22   ` Charles Duffy
2008-08-07 11:43 ` Sven-Haegar Koch
2008-08-07 14:55   ` Charles Duffy
2008-08-07 15:16     ` Grant Taylor
2008-08-07 16:03       ` Jan Engelhardt
2008-08-07 19:35         ` Grant Taylor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='g7da9g$21r$1@ger.gmane.org' \
    --to=charles_duffy@messageone.com \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox