This shows you the differences between two versions of the page.
Both sides previous revision Previous revision | Next revision Both sides next revision | ||
docs:lxc [2014-07-06 11:45] glen typo |
docs:lxc [2014-07-07 10:12] matkor [network using macvlan in bridge mode] |
||
---|---|---|---|
Line 138: | Line 138: | ||
- you can't filter guest straffic from host's firewall | - you can't filter guest straffic from host's firewall | ||
- host can use seme default interface with and without guests running. | - host can use seme default interface with and without guests running. | ||
- | - you HAVE to set mac. If not - on every container start you'll have different one (your router will not pass the traffic). | + | - one have better to set static MAC address. If not - on every container start you'll have different MAC generated and your router may have problems with passing traffic. |
- | - iptables is initialized from lxc.hook.pre-mount hook (ran in the container's namespace and having macvlan interface visible) | + | - iptables is initialized from lxc.hook.pre-mount hook (ran in the container's namespace and having guest macvlan interface visible) |
first boot with ''hwaddr'' line disabled, look what the random address was assigned, set it in config. | first boot with ''hwaddr'' line disabled, look what the random address was assigned, set it in config. |