Private vlans in OVS

Hey guys,

for DMZ’s I would love to support private VLANs - meaning each VM can not communicate with any other system, except the router that does the upstream connection.

It is possible with OVS by adding some flows.

It would be nicest if I could basically configure this as a vnet property though.

Do you think it would be possible to do this WITH OpenNebula? How would I go about it?

1 Like

Anyone? BUMP! :slight_smile:

still, OVS doesn’t support private VLANs?

Absolutely, OpenNebula provides network isolation through VLANs tagging ports and basic network filtering through OpenFlow.

I recommend you to have a look here where the OVS OpenNebula driver is discussed.

Best,
Victor.