
I am using ovirt 4.3. I am in need to isolate all my VM from each other (without using VLAN) except to a virtual gateway which is also the DHCP server. Basically only allowing traffic from 1 MAC address to another MAC address. Everything else should be filter out by ovirt filtering subsystem How will I go about that? I can see in network profile the ability to set different filter but can't find a way to create new filter. Thanks for your help Pascal

On Fri, Nov 13, 2020 at 5:13 AM <pascal@butterflyit.com> wrote:
I am using ovirt 4.3. I am in need to isolate all my VM from each other (without using VLAN) except to a virtual gateway which is also the DHCP server.
Basically only allowing traffic from 1 MAC address to another MAC address. Everything else should be filter out by ovirt filtering subsystem
How will I go about that? I can see in network profile the ability to set different filter but can't find a way to create new filter.
Does the Doc Text of *Bug 1009608* <https://bugzilla.redhat.com/show_bug.cgi?id=1009608> - [RFE] Limit east-west traffic of VMs with network filter https://bugzilla.redhat.com/show_bug.cgi?id=1009608 explain the configuration of the filter? Please note that there will be isolated ports https://www.ovirt.org/develop/release-management/features/network/isolated-p... available in ovirt-4.4.3 on CentOS 8.3 , which might address your scenario even better.
Thanks for your help
Pascal _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/QIYX2SA7TBEFGA...

Thank you That is exactly what I was looking for. Any chance it could be back ported to 4.3. Maybe list the rules and I could use rest API to add it to my court install I'm not eager to move yet to 4.4 since I'm reading on this list lot of people have issue migrating and I have 20 hosts running currently Get Outlook for Android<https://aka.ms/ghei36> ________________________________ From: Dominik Holler <dholler@redhat.com> Sent: Friday, November 13, 2020 6:21:56 AM To: Pascal DeMilly <Pascal@butterflyit.com> Cc: users <users@ovirt.org> Subject: Re: [ovirt-users] Network profile filtering On Fri, Nov 13, 2020 at 5:13 AM <pascal@butterflyit.com<mailto:pascal@butterflyit.com>> wrote: I am using ovirt 4.3. I am in need to isolate all my VM from each other (without using VLAN) except to a virtual gateway which is also the DHCP server. Basically only allowing traffic from 1 MAC address to another MAC address. Everything else should be filter out by ovirt filtering subsystem How will I go about that? I can see in network profile the ability to set different filter but can't find a way to create new filter. Does the Doc Text of Bug 1009608<https://bugzilla.redhat.com/show_bug.cgi?id=1009608> - [RFE] Limit east-west traffic of VMs with network filter https://bugzilla.redhat.com/show_bug.cgi?id=1009608 explain the configuration of the filter? Please note that there will be isolated ports https://www.ovirt.org/develop/release-management/features/network/isolated-p... available in ovirt-4.4.3 on CentOS 8.3 , which might address your scenario even better. Thanks for your help Pascal _______________________________________________ Users mailing list -- users@ovirt.org<mailto:users@ovirt.org> To unsubscribe send an email to users-leave@ovirt.org<mailto:users-leave@ovirt.org> Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/QIYX2SA7TBEFGA...
participants (3)
-
Dominik Holler
-
Pascal DeMilly
-
pascal@butterflyit.com