Is there a way to isolate a physical NIC so that it can only be used by a guest machine, without any interaction with the host? I want to set up a guest that I can access remotely across the Internet, but don't want my Host being accessible. So far, I've used a bridged network connection, but the best that seems to do is share the NIC between the host and the guest.
On a related note, I looked for this, but couldn't find an answer: If some-one or -thing penetrated my guest, would they have access to my host machine as well? Is there any documentation on the security best practices for setting something akin to a DMZ for a guest?
Any help would be appreciated. Thanks!
Isolate Physical NIC to Guest
-
Perryg
- Site Moderator
- Posts: 34369
- Joined: 6. Sep 2008, 22:55
- Primary OS: Linux other
- VBox Version: OSE self-compiled
- Guest OSses: *NIX
Re: Isolate Physical NIC to Guest
Setup a separate (USB adapter) that the guest uses. wifi or Ethernet. will make access to the guest alone.
Do not use shared folders and firewall the guest from the host.
Do not use shared folders and firewall the guest from the host.
-
sar881
- Posts: 2
- Joined: 29. Apr 2011, 18:26
- Primary OS: MS Windows XP
- VBox Version: OSE other
- Guest OSses: XP
Re: Isolate Physical NIC to Guest
The NIC is not a USB device, rather, a PCI card. Will this method still work?
-
Perryg
- Site Moderator
- Posts: 34369
- Joined: 6. Sep 2008, 22:55
- Primary OS: Linux other
- VBox Version: OSE self-compiled
- Guest OSses: *NIX
Re: Isolate Physical NIC to Guest
No.
VirtualBox can not separate the PCI device from the host. But if you want your guest to work as you said the USB route is your only option and it does work.
VirtualBox can not separate the PCI device from the host. But if you want your guest to work as you said the USB route is your only option and it does work.
-
BillG
- Volunteer
- Posts: 5106
- Joined: 19. Sep 2009, 04:44
- Primary OS: MS Windows 10
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Windows 10,7 and earlier
- Location: Sydney, Australia
Re: Isolate Physical NIC to Guest
If you want to do this with PCI NICs you need two of them. You dedicate one to the host and one to the guest. The guest only NIC has only the bridged networking filter enabled (no access to the host IP stack) while the host only NIC has the bridged networking filter disabled (no access to the guest).
Bill