Where should I add my custom iptables rules on RHEV-H?

Solution Verified - Updated -

Issue

  • I have installed several hypervisors now and the default iptables setup for these included these lines at the end:
  -A FORWARD -m physdev ! --physdev-is-bridged -j REJECT --reject-with icmp-host-prohibited
  • If I add a number of additional commands to open up the server to certain IP numbers or ports, should this command go before / after or does it not make any difference?
  • It does not look as if this is opening the hypervisor to more accessibility, so it is not clear where I would best add the line in my expanded iptables list.

Environment

  • Red Hat Enterprise Virtualization v3.1

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content