Page 1 of 1

Iptables with host-only networking

Posted: 24. Aug 2009, 15:15
by ceving
I would like to configure some iptables rules as soon as any vboxnet interface comes up. But the interfaces are not controlled by /etc/network/interfaces like all other interfaces on my Debian host. Is there any other kind of hook which can be used to run some iptables commands after an VirtualBox interface became available?

Re: Iptables with host-only networking

Posted: 24. Aug 2009, 15:50
by sej7278
why don't you use bridged networking, then it more like a real network interface.

i don't see the point of firewalling an interface that can only connect to the host, you might as well not bother with networking at all!

Re: Iptables with host-only networking

Posted: 24. Aug 2009, 16:01
by ceving
sej7278 wrote:why don't you use bridged networking, then it more like a real network interface.
Host only interfaces are unreal interfaces?

Re: Iptables with host-only networking

Posted: 24. Aug 2009, 18:37
by sej7278
ceving wrote:
sej7278 wrote:why don't you use bridged networking, then it more like a real network interface.
Host only interfaces are unreal interfaces?
well it only sends traffic between the host and guest (not lan or internet) so a little pointless yes!

Re: Iptables with host-only networking

Posted: 27. Aug 2009, 02:02
by blinky
sej7278 wrote:
ceving wrote:
sej7278 wrote:why don't you use bridged networking, then it more like a real network interface.
Host only interfaces are unreal interfaces?
well it only sends traffic between the host and guest (not lan or internet) so a little pointless yes!
Not quite true. If your real interface is eth0, then if you enabling forwarding in (/etc/sysctl.conf) and set a rule to NAT all traffic out of eth0 you end up wih a private virtual network (with multiple VM's if you require) that can talk to the everything outside of eth0 (lan/internet).

Add in port forwarding rules to to the host and the VM's can provide services to things on the other side of eth0

I use it for testing out idea's, works well.

Re: Iptables with host-only networking

Posted: 27. Aug 2009, 16:36
by ceving
blinky wrote:Add in port forwarding rules to to the host and the VM's can provide services to things on the other side of eth0
Thanks for explaining this. But how about my original question?