Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: IP Alias with iptables
Date: Tue, 20 Apr 2004 19:27:14 +0100	[thread overview]
Message-ID: <200404201927.14766.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <16517.26251.561739.758706@saint.heaven.net>

On Tuesday 20 April 2004 7:06 pm, Dick St.Peters wrote:

(Quoted from Alistair Tonner):

> > > 	Aliased (stacked) interfaces ARE NOT SECURE.  Period.

(Quoted from me):

> > Indeed.   I would like to see this emphasised more in the netfilter
> > howtos & tutorials.   Multiple addresses on one interface are all very
> > well, so long as they exist within the same subnet; however anyone trying
> > to use multiple *network* addresses on one physical interface is
> > defeating their security by ignoring what the different OSI network
> > layers mean.
>
> I want to add some qualification to these statements.  Aliased
> interfaces do not inherently introduce any insecurity in cases
> where you don't care about subnet separation.

I agree.   However, Alistair and I were not claiming that aliased interfaces 
introduce an insecurity where you don't require any security - we were simply 
saying that you cannot (should not) use them where you require to have secure 
separation of your subnets.

If you want to overlap two logical networks on one physical infrastructure, 
and you do not require any security between them, then aliased interfaces are 
ideal for the job.

However, if you are trying to keep two logical networks securely separate from 
each other (as the original poster wanted to do), then aliased interfaces 
will defeat your attempts at this.

Regards,

Antony.

-- 
There are two possible outcomes:

 If the result confirms the hypothesis, then you've made a measurement.
 If the result is contrary to the hypothesis, then you've made a discovery.

 - Enrico Fermi

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-04-20 18:27 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-04-19 15:41 IP Alias with iptables Rodrigo Haces
2004-04-19 14:53 ` Antony Stone
2004-04-19 16:07   ` Rodrigo Haces
2004-04-19 15:25     ` Antony Stone
2004-04-19 16:12       ` Alistair Tonner
2004-04-19 21:31         ` Antony Stone
2004-04-20  3:08           ` Rodrigo Haces
2004-04-20  7:33             ` Antony Stone
2004-04-20 23:39               ` Rodrigo Haces
2004-04-21  7:50                 ` Antony Stone
2004-04-20 18:06           ` Dick St.Peters
2004-04-20 18:27             ` Antony Stone [this message]
2004-04-19 16:55       ` Rodrigo Haces
2004-04-19 15:43     ` Cedric Blancher
2004-04-19 15:22 ` Michael Gale
     [not found] <006901c4261e$01f081f0$0c00a8c0@pepelui>
2004-04-19 16:20 ` Rodrigo Haces
2004-04-19 15:28   ` Alexis

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200404201927.14766.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox