有没有办法用Linux桥实现这个例子.将VM隔离开来?也许通过ebtables?
我没有服务器与手头的桥梁,但我会做这样的事情:
ebtables -P FORWARD DROP ebtables -F FORWARD ebtables -A FORWARD -i $uplinkPort -j ACCEPT # let the traffic flow from uplink to any ports ebtables -A FORWARD -o $uplinkPort -j ACCEPT # let the traffic flow from any ports to uplink