May 22, 2013, 10:09:32 pm
Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Welcome to Hurricane Electric's Tunnelbroker.net forums!
Home
Help
Search
Login
Register
Hurricane Electric's IPv6 Tunnel Broker Forums
>
General IPv6 Topics
>
IPv6 on Linux & BSD & Mac
>
How to prevent nd spoofing by xen domU guests?
Pages: [
1
]
« previous
next »
Print
Author
Topic: How to prevent nd spoofing by xen domU guests? (Read 728 times)
tdwebste
Newbie
Posts: 1
How to prevent nd spoofing by xen domU guests?
«
on:
April 18, 2012, 11:26:11 am »
In this configuration untrusted guests are given full root access to their xen domU
I currently have arptable and ebtable rules in the dom0 to make arp spoofing from a domU a little more difficult.
domU# ifconfig
eth0 Link encap:Ethernet HWaddr 01:02:03:04:05:06
inet addr:123.123.123.123 .......................
dom0# arptables -L
-j ACCEPT -s nlnog.nmsrv.com --src-mac 01:02:03:04:05:06 --opcode Reply
-j ACCEPT -s nlnog.nmsrv.com --src-mac 01:02:03:04:05:06 --opcode Request
dom0# ebtables -L
-p IPv4 -o vif5.0 --ip-dst 123.123.123.123 -j ACCEPT
-p IPv4 -i vif5.0 --ip-src 123.123.123.123 -j ACCEPT
-p IPv4 -o vif5.0 -j DROP
-p IPv4 -i vif5.0 -j DROP
I am looking for recommendations how to protect against domU nd spoofing.
Logged
Pages: [
1
]
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Tunnelbroker.net Specific Topics
-----------------------------
=> News & Updates
=> Questions & Answers
=> HE's Widgets & Gadgets
-----------------------------
IPv6 Certification Program Topics
-----------------------------
=> General Discussion
=> Suggest a Test!
-----------------------------
DNS.HE.NET Topics
-----------------------------
=> General Questions & Suggestions
-----------------------------
General IPv6 Topics
-----------------------------
=> IPv6 Basics & Questions & General Chatter
=> IPv6 on Linux & BSD & Mac
=> IPv6 on Windows
=> IPv6 on Routing Platforms
=> IPv6 Software Applications & Hardware Appliances
Loading...