I don't think ebtables will work because you'll be able to contact the gateway of another compute node. This patch has been tested and prevent all VMs from all compute nodes from accessing any compute node using nova-network.
(I don't know much of ebtables so I can't be 100% sure of this statement but iptables does the trick)
I don't think ebtables will work because you'll be able to contact the gateway of another compute node. This patch has been tested and prevent all VMs from all compute nodes from accessing any compute node using nova-network.
(I don't know much of ebtables so I can't be 100% sure of this statement but iptables does the trick)