From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: IP Alias with iptables
Date: Tue, 20 Apr 2004 19:27:14 +0100 [thread overview]
Message-ID: <200404201927.14766.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <16517.26251.561739.758706@saint.heaven.net>
On Tuesday 20 April 2004 7:06 pm, Dick St.Peters wrote:
(Quoted from Alistair Tonner):
> > > Aliased (stacked) interfaces ARE NOT SECURE. Period.
(Quoted from me):
> > Indeed. I would like to see this emphasised more in the netfilter
> > howtos & tutorials. Multiple addresses on one interface are all very
> > well, so long as they exist within the same subnet; however anyone trying
> > to use multiple *network* addresses on one physical interface is
> > defeating their security by ignoring what the different OSI network
> > layers mean.
>
> I want to add some qualification to these statements. Aliased
> interfaces do not inherently introduce any insecurity in cases
> where you don't care about subnet separation.
I agree. However, Alistair and I were not claiming that aliased interfaces
introduce an insecurity where you don't require any security - we were simply
saying that you cannot (should not) use them where you require to have secure
separation of your subnets.
If you want to overlap two logical networks on one physical infrastructure,
and you do not require any security between them, then aliased interfaces are
ideal for the job.
However, if you are trying to keep two logical networks securely separate from
each other (as the original poster wanted to do), then aliased interfaces
will defeat your attempts at this.
Regards,
Antony.
--
There are two possible outcomes:
If the result confirms the hypothesis, then you've made a measurement.
If the result is contrary to the hypothesis, then you've made a discovery.
- Enrico Fermi
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2004-04-20 18:27 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-19 15:41 IP Alias with iptables Rodrigo Haces
2004-04-19 14:53 ` Antony Stone
2004-04-19 16:07 ` Rodrigo Haces
2004-04-19 15:25 ` Antony Stone
2004-04-19 16:12 ` Alistair Tonner
2004-04-19 21:31 ` Antony Stone
2004-04-20 3:08 ` Rodrigo Haces
2004-04-20 7:33 ` Antony Stone
2004-04-20 23:39 ` Rodrigo Haces
2004-04-21 7:50 ` Antony Stone
2004-04-20 18:06 ` Dick St.Peters
2004-04-20 18:27 ` Antony Stone [this message]
2004-04-19 16:55 ` Rodrigo Haces
2004-04-19 15:43 ` Cedric Blancher
2004-04-19 15:22 ` Michael Gale
[not found] <006901c4261e$01f081f0$0c00a8c0@pepelui>
2004-04-19 16:20 ` Rodrigo Haces
2004-04-19 15:28 ` Alexis
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200404201927.14766.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox