-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
On 08/26/2015 02:54 AM, Marek Marczykowski-Górecki wrote:
> On Mon, Aug 17, 2015 at 11:00:44PM +0100, Unman wrote:
>> On Sat, Aug 15, 2015 at 07:07:36PM +0000, Qubed One wrote:
>>>
>>> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
>>>
>>> Hi, is there an upper limit to the number of entries under the
>>> firewall tab in Qubes VM Manager?
>>>
>>> When I try to start a vm in Qubes 3rc2 with too many entries
>>> allowed, denying the rest, I get the attached error.
>>>
>>> The vm is working with roughly three dozen entries now.
>>>
>>> The same error is presented with both app-vms and proxy-vms.
>>>
>>> Thanks in advance!
>
>> You're running very close to the limit, which is, I think, 39.
>> Interestingly, if you try with more, the fw seems to have the
>> full iptables rules written, but the VM never completes startup
>> as you've discovered.
>
> Maximum is 3kb of iptables script, which is indeed about 39 rules.
> We will rework that firewall mechanism in Qubes 4.0, but until then
> you can use `qubes-firewall-user-script`[1] as a workaround - VM
> IPs are static (and protected against spoofing) so it should be
> rather easy to add additional rules there.
>
> [1]
https://www.qubes-os.org/doc/UserDoc/ConfigFiles/
>
>
Good to know. Thanks!
-----BEGIN PGP SIGNATURE-----
iQJ8BAEBCgBmBQJV3fYRXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2N0FGNkY4NTIxMzYxNjI1REE1MjY1QTcw
MUNBRjYzOTFBQkM0OTgzAAoJEAHK9jkavEmDox8P/1xSWKiE03jFskRhBHOpuD07
Nrs8kBRmz8McdIYq37Yf32uKrz7CV9Ib+tsHvOA4p0vKiJyn1i6zi43LCdWiHjuv
vFVWUMDiI/j45v2ytoY1zGpZSpDB5z8Wz7csnuaLw6ikkmcjFHeB6a/Ubvmq9JBR
lfKsNURxE1FKa4N4Rl9037dK0CMeRx1TNIn6qQ+yXskE1lKjSDXd4+OApBtWTJgg
qBTeTJlCORodjDWBizS8QXE7Pzq8H1b48TQ4O+nq8e5RaFt41YkpCwh5zBgGqPip
xz78B7BScuaFUjOUATmyMMZTshtp20QDV1zRBlwANN6N9NDjfXedtlY//2DSkgKc
RoKgRfmftu3rTQnfxTx7hTUwBda6Wbjfbu8jXMSi4tAHV6PZH0rI0UzDtezwRm08
XnLPjwri3l7bvo1WftwllDPoMhu1yC5veW+h1CWTaNaIUxIS+icBCNpHx+5EWMMP
Jm3s1Lu5u6jN5qDUPXNWeb4G341rm1PDxrjVJGYBidNpTBg431/EmRXrNKP6t8kF
1OojedY/2TUeY60qK+JEYZAemTr3WeNY5SHuMH+KFwakmHZ26Mt45ZM+m8OiZKGn
hWKDHzzXa7mITYcHTfNLhPyKDe3leJAHHKKoH+dgAUZfj0gMalPnmaWnW12VR4Uz
cdGUVl5+Yysm0BBEEbDX
=Xcjp
-----END PGP SIGNATURE-----