I am using kvm with bridge networking and I want to limit packets per second for all virtual machines.
I know how to do that with iptables, but it's not working. All iptables rules don't apply to the routed vm ips, although net.bridge.bridge-nf-call-iptables = 1
.
Best Answer
You need to tell the kernel to pass packets passing through the bridge to netfilter/iptables:
So to filter IPv4 traffic, you need to set:
If you're using VLAN's, you'll probably need to enable the
filter-vlan-tagged
option too.