From 8d2423af0d1cb2771a6aea432aeeceb52399fa2e Mon Sep 17 00:00:00 2001 From: Quentin Smith Date: Wed, 9 Mar 2011 18:18:14 -0500 Subject: [PATCH] Don't enable proxy arp on every interface, just the public one --- debian/changelog | 7 +++++++ debian/invirt-xen-config.init | 2 +- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/debian/changelog b/debian/changelog index 693f2de..e9318d3 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,10 @@ +invirt-xen-config (0.0.32) unstable; urgency=low + + * Don't enable proxy arp on every interface, just the public one (fixes + problems with reachability on the backend network!) + + -- Quentin Smith Wed, 09 Mar 2011 18:18:06 -0500 + invirt-xen-config (0.0.31) unstable; urgency=low * Only run arpspoof when NICs are brought online (this potentially fixes diff --git a/debian/invirt-xen-config.init b/debian/invirt-xen-config.init index f5e29c3..5741943 100755 --- a/debian/invirt-xen-config.init +++ b/debian/invirt-xen-config.init @@ -23,7 +23,7 @@ do_startup() { gen_files echo 1 >/proc/sys/net/ipv4/ip_forward - for i in all default; do + for i in $(invirt-getconf xen.iface) default; do echo 1 >/proc/sys/net/ipv4/conf/$i/rp_filter echo 1 >/proc/sys/net/ipv4/conf/$i/proxy_arp done -- 1.7.9.5