Skip to content

Instantly share code, notes, and snippets.

@kevsersrca
Forked from wido/libvirt-network-filter.xml
Created February 6, 2018 08:17
Show Gist options
  • Save kevsersrca/8caf63fa7841c2d14e6a1e1ee9a5fc09 to your computer and use it in GitHub Desktop.
Save kevsersrca/8caf63fa7841c2d14e6a1e1ee9a5fc09 to your computer and use it in GitHub Desktop.
Simple Network Filter for libvirt
<filter name='network_filter_1' chain='ipv4' priority='-700'>
<uuid>64b80046-9a9d-40c2-8782-ed5878146262</uuid>
<rule action='drop' direction='out' priority='500'>
<mac match='no' srcmacaddr='52:54:00:01:ad:9d'/>
</rule>
<rule action='return' direction='out' priority='500'>
<ip srcipaddr='192.168.100.101'/>
</rule>
<rule action='return' direction='out' priority='501'>
<ip srcipaddr='192.168.100.201'/>
</rule>
<rule action='return' direction='out' priority='502'>
<ip srcipaddr='10.0.0.0' srcipmask='24'/>
</rule>
<rule action='drop' direction='out' priority='1000'/>
<rule action='accept' direction='in' priority='500'>
<icmp/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='22'/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='80'/>
</rule>
<rule action='accept' direction='in' priority='500'>
<tcp dstportstart='443'/>
</rule>
<rule action='drop' direction='in' priority='1000'>
<all/>
</rule>
</filter>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment