Skip to content

Instantly share code, notes, and snippets.

@wido
Created January 6, 2016 15:03
Show Gist options
  • Save wido/c2d20dcec770973f4e2e to your computer and use it in GitHub Desktop.
Save wido/c2d20dcec770973f4e2e to your computer and use it in GitHub Desktop.
Simple Network Filter for libvirt
<filter name='network_filter_1' chain='ipv4' priority='-700'>
<uuid>64b80046-9a9d-40c2-8782-ed5878146262</uuid>
<rule action='drop' direction='out' priority='500'>
<mac match='no' srcmacaddr='52:54:00:01:ad:9d'/>
</rule>
<rule action='return' direction='out' priority='500'>
<ip srcipaddr='192.168.100.101'/>
</rule>
<rule action='return' direction='out' priority='501'>
<ip srcipaddr='192.168.100.201'/>
</rule>
<rule action='return' direction='out' priority='502'>
<ip srcipaddr='10.0.0.0' srcipmask='24'/>
</rule>
<rule action='drop' direction='out' priority='1000'/>
<rule action='accept' direction='in' priority='500'>
<icmp/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='22'/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='80'/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='443'/>
</rule>
<rule action='drop' direction='in' priority='1000'>
<all/>
</rule>
</filter>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment