Re: Xen security / MAC hijack
Grant Taylor <[email protected]> Sun, 25 Nov 2007 23:28:54 -0600
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
On 11/23/2007 7:47 AM, Stefan de Konink wrote: > Xen host 1 has a hwaddr. > > Xen host 2 steels hwaddr of host 1. > > At that moment Xen host 1 is not reachable anymore. Ah, this is a fun scenario. ... and one that is rather difficult to secure against. > Now I tried to prevent ARP packets in the forwarding chain that didn't > match the mac that Xen reports as valid. But it seems the bridge get > informed about this 'new interface' upon ifconfig eth0 up in an other > way, or via an other route. Blocking ARPs is not enough. Equipment connected to the bridge will learn the MAC address stolen by domain 2 other ways, i.e. GARP, sending traffic, etc. > Is it possible to limit a source mac to a specific interface in a way > that also ARP replies are blocked that indicate other macs? You need to intelligently forward traffic between your domains. You will have to educate your bridge about what MAC addresses are allowed to be where. Grant. . . . ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/