Skip to content

Commit

Permalink
FAQ: Mention conntrack capability for packet filtering.
Browse files Browse the repository at this point in the history
The existing explanation didn't tell user the conntrack capability
and user may be unaware of the stateful feature of OVS.

Signed-off-by: Han Zhou <[email protected]>
Signed-off-by: Ben Pfaff <[email protected]>
  • Loading branch information
hzhou8 authored and blp committed Oct 31, 2016
1 parent 0612d73 commit 0b1545b
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion FAQ.rst
Original file line number Diff line number Diff line change
Expand Up @@ -886,7 +886,9 @@ Q: Open vSwitch does not seem to obey my packet filter rules.
would add an IP address, as discussed elsewhere in the FAQ.)

For simple filtering rules, it might be possible to achieve similar results
by installing appropriate OpenFlow flows instead.
by installing appropriate OpenFlow flows instead. The OVS conntrack
feature (see the "ct" action in ovs-ofctl(8)) can implement a stateful
firewall.

If the use of a particular packet filter setup is essential, Open vSwitch
might not be the best choice for you. On Linux, you might want to consider
Expand Down

0 comments on commit 0b1545b

Please sign in to comment.