"Workstation" Product defaults to wide-open firewall

Kevin Kofler kevin.kofler at chello.at
Tue Dec 9 18:54:10 UTC 2014


Stephen Gallagher wrote:
> * Port forward between two interfaces, which is really useful with
> virtualizationFedoraWorkstation (default, active)
>   interfaces: em1 virbr0 virbr0-nic wlp4s0
>   sources:
>   services: dhcpv6-client dns freeipa-ldap freeipa-ldaps samba-client
> ssh
>   ports:
>   masquerade: no
>   forward-ports:
>   icmp-blocks:
>   rich rules:

QEMU takes a command-line parameter that forwards a port to a host port for 
you. That's how I have always handled this. Don't ask me why libvirt 
defaults to that overly-complicated bridging setup instead of just giving 
you a table of port forwards to pass to the QEMU command line.

>   services: dhcpv6-client dns freeipa-ldap freeipa-ldaps samba-client
> ssh

With the default Workstation policy, does that enumerate all 129022 open 
unprivileged ports?

        Kevin Kofler



More information about the devel mailing list