mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2024-09-19 22:21:27 +00:00
10 lines
353 B
XML
10 lines
353 B
XML
|
<filter name='no-arp-ip-spoofing' chain='arp-ip' priority='-510'>
|
||
|
<!-- no arp spoofing -->
|
||
|
<!-- drop if ipaddr does not belong to guest -->
|
||
|
<rule action='return' direction='out' priority='400' >
|
||
|
<arp match='yes' arpsrcipaddr='$IP' />
|
||
|
</rule>
|
||
|
<!-- drop everything else -->
|
||
|
<rule action='drop' direction='out' priority='1000' />
|
||
|
</filter>
|