allow inbound ARP for VMs
This commit is contained in:
parent
4e6277aed7
commit
76e832a3f6
@ -24,6 +24,7 @@ add_nft_rules() {
|
||||
nft add chain netdev deteemacvtap ${ifname}_ou "{ type filter hook egress device ${ifname} priority 0; policy accept; }"
|
||||
# return if the rules already exist
|
||||
nft list chain netdev deteemacvtap ${ifname}_in | grep ether && return 0
|
||||
nft add rule netdev deteemacvtap ${ifname}_in ether type arp accept
|
||||
nft add rule netdev deteemacvtap ${ifname}_in ether daddr != ${vtap_addr} drop
|
||||
nft list chain netdev deteemacvtap ${ifname}_ou | grep ether && return 0
|
||||
nft add rule netdev deteemacvtap ${ifname}_ou ether saddr != ${vtap_addr} drop
|
||||
|
Loading…
Reference in New Issue
Block a user