Linux Netfilter discussions
 help / color / mirror / Atom feed
* VLANs
@ 2011-01-10 17:42 Jonathan Tripathy
  2011-01-10 21:33 ` VLANs John Haxby
  0 siblings, 1 reply; 15+ messages in thread
From: Jonathan Tripathy @ 2011-01-10 17:42 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

I wish to use VLANs on my Linux Xen hosts to seperate managed customer 
networks.

Can anybody please give me some pointers on how to make the network 
secure so no-one can VLAN hop?

At the minute, I plan to set up one bridge per customer, and use linux 
vconfig to add an if to the bridge (which I believe strips all tags). 
Then, all the respective customer Xen DomU (VM) interfaces will connect 
to the bridge.

Thanks

^ permalink raw reply	[flat|nested] 15+ messages in thread
* VLANs
@ 2011-01-05 12:12 Jonathan Tripathy
  2011-01-06  7:32 ` VLANs John Haxby
  0 siblings, 1 reply; 15+ messages in thread
From: Jonathan Tripathy @ 2011-01-05 12:12 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

If I plug my Xen host to a VLAN aware switch using a trunk port (I.e. 
all frames are tagged), can my Xen host, using a linux bridge, strip out 
all tagging and send frame to correct Xen VM? (And vice versa)

I wish to have isolated and secure networks that cannot communicate 
except via my VLAN aware firewall (pfsense)

Thanks

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2011-01-11 17:21 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-10 17:42 VLANs Jonathan Tripathy
2011-01-10 21:33 ` VLANs John Haxby
2011-01-10 22:15   ` VLANs Jonathan Tripathy
2011-01-11  8:19     ` VLANs Thomas Berg
2011-01-11 10:26       ` VLANs Jonathan Tripathy
2011-01-11 10:42     ` VLANs John Haxby
2011-01-11 10:57       ` VLANs Jonathan Tripathy
     [not found]         ` <4D2C47DB.10702@oracle.com>
2011-01-11 12:24           ` VLANs Jonathan Tripathy
2011-01-11 12:48             ` VLANs John Haxby
2011-01-11 12:52               ` VLANs Jonathan Tripathy
2011-01-11 17:12                 ` VLANs John Haxby
2011-01-11 17:15                   ` VLANs Jonathan Tripathy
2011-01-11 17:21                     ` VLANs John Haxby
  -- strict thread matches above, loose matches on Subject: below --
2011-01-05 12:12 VLANs Jonathan Tripathy
2011-01-06  7:32 ` VLANs John Haxby

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox