Posts

Showing posts with the label kvm

Docker and KVM on the same host and networking

  If you are trying to get Docker and KVM to work on the same host then you will find that the networking is a  bit icky. You'll need to tell iptables to allow forwarding on your network interface. As I always to things using a bridge (makes it easier to change network card if needed), I use br0 in this example. cat /dev/null [Unit] Description = Apply iptables rules [Service] Type=oneshot ExecStart=/bin/sh -c 'iptables -A FORWARD -i br0 -o br0 -j ACCEPT' [Install] WantedBy=network-online.target EOF   Then you need to enable it and restart the service (I'd restart the host): sudo systemctl daemon-reload \ && sudo systemctl enable restore-iptables-rules.service \ && sudo systemctl start restore-iptables-rules.service   That should be it, now your KVM guests will be able to reach the network. (there, of cause will be other things like enabling of forwarding which is also required). 

Ubuntu: Networking - Docker and KVM on the same box

If you like me have a box which is running everything, like; Docker, kvm and lxc then you probably also once in a while get gray hair from sorting out networking.  So Docker like to control networking and I let it - only exception is that I'm having a separate bridge (macvlan) for everything Docker as it does sometimes makes life easier (not often). But as Docker see everything, even with multiple network cards / bridges as one whole, it does apply it's iptables rules to everything. Which does cause some problems for kvm and lxc.  One easy way to allow communcation to the kvm vm's via your bridge (if you use bridged networking) is to allow it: iptables -A FORWARD -i br0 -o br0 -j ACCEPT Replace 'br0' with what ever you use as bridge for kvm / lxc. To have this to execute automatically everytime you retart networking (reboot the box) create the following file: /etc/systemd/system/restore-iptables-rules.service With this content: [Unit] Description = Apply iptab...

RHEL6 - disable IPv6 on an interface

I've been having fun upgrading, or should one say migrating to RHEL6 ( Scientific Linux 6.1 ). As run KVM (Virtualization) I have a bridge running for my VM to connect to the network. Now I suddenly noticed that IPv6 was enable on my 'eth0' which is part of the bridge, this should not happen as it can cause communication issues (yes I got IPv6 enabled devices on my network). So after a bit of searching I found a bug from Redhat ( bug#496444 ) which states that IPV6INIT=no does not work for a single interface, in fact it does not work at all. The bug is still open. Now after a bit of searching I found something which works just fine: # echo 1 > /proc/sys/net/ipv6/conf/ethX/disable_ipv6 To make this permanent add it to /etc/rc.d/rc.local then IPv6 will get disabled every time the server restarts.