unix:virtualization:kvm:ebtables
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revision | Last revisionBoth sides next revision | ||
unix:virtualization:kvm:ebtables [2022/07/22 16:11] – rodolico | unix:virtualization:kvm:ebtables [2022/07/22 16:22] – rodolico | ||
---|---|---|---|
Line 13: | Line 13: | ||
| router | 00: | | router | 00: | ||
| manage | 00: | | manage | 00: | ||
+ | |||
+ | Win10 is a //virtual// inside our network. We need to be able to access it from //manage//, and also it needs to access the Internet via //router//. We also want to access //Win10// via RDP over VPN. However, //Win10// should not ' | ||
+ | |||
+ | ebtables works with MAC addresses, so we track the MAC's. The above MAC's are samples randomly chosen from those assigned for some forms of virtualization; | ||
+ | |||
+ | Basically, we add rules to allow access between //Win10// and //router//, and //Win10// and //manage//, then we add rules to not allow any other access. | ||
+ | |||
+ | Not sure why, but we need protocols 0x800 and 0x806 (IPv4 and ARP) specifically allowed to the router or this will not work. You can still access from //manage// but not over a VPN connection. Still researching that. | ||
Line 27: | Line 35: | ||
ebtables -A FORWARD -s 00: | ebtables -A FORWARD -s 00: | ||
# not sure why, but we need these two protocols usable | # not sure why, but we need these two protocols usable | ||
- | ebtables -A FORWARD -s 00: | + | ebtables -A FORWARD -s 00: |
- | ebtables -A FORWARD -s 00: | + | ebtables -A FORWARD -s 00: |
# Drop all other traffic where Win10 is the source | # Drop all other traffic where Win10 is the source | ||
ebtables -A FORWARD -s 00: | ebtables -A FORWARD -s 00: | ||
Line 36: | Line 44: | ||
ebtables -L | ebtables -L | ||
</ | </ | ||
+ | |||
+ | ===== Links ===== | ||
+ | - https:// | ||
+ | - https:// | ||
+ | - https:// | ||
+ | - http:// | ||
+ | - https:// | ||
+ | - |
unix/virtualization/kvm/ebtables.txt · Last modified: 2022/07/23 01:33 by rodolico