XenServer Host Networking Protections

Background

In a multi-tenant cloud environment a host machine needs to be able to enforce network isolation amongst guest instances, at both layer two and layer three. The rules prevent guests from taking and using unauthorized IP addresses, sniffing other guests traffic, and prevent ARP poisoning attacks. IPv6 attacks will need to be factored in as well.

Assumptions

Dependency

Antony Messerli from Rackspace has working scripts for applying iptables, ebtables, and arptables rules on the host. This blueprint relies on those scripts.

Requirements

Wiki: XenServerNetworkingProtections (last edited 2010-12-13 23:15:20 by ant)