The existing explanation didn't tell user the conntrack capability
and user may be unaware of the stateful feature of OVS.
Signed-off-by: Han Zhou <zhouhan@gmail.com>
Signed-off-by: Ben Pfaff <blp@ovn.org>
would add an IP address, as discussed elsewhere in the FAQ.)
For simple filtering rules, it might be possible to achieve similar results
- by installing appropriate OpenFlow flows instead.
+ by installing appropriate OpenFlow flows instead. The OVS conntrack
+ feature (see the "ct" action in ovs-ofctl(8)) can implement a stateful
+ firewall.
If the use of a particular packet filter setup is essential, Open vSwitch
might not be the best choice for you. On Linux, you might want to consider