Hello.
Is it possible to Firewall the physical Network Interface Card to apply to All Virtual NICs created
with VirtualBox ?
Thank you.
Firewall The Physical NIC for all Virtual NICs
-
mpack
- Site Moderator
- Posts: 39134
- Joined: 4. Sep 2008, 17:09
- Primary OS: MS Windows 10
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Mostly XP
Re: Firewall The Physical NIC for all Virtual NICs
Just use NAT mode in the guests?
-
Smellz
- Posts: 35
- Joined: 6. Jul 2009, 12:42
- Primary OS: Debian other
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: debian mint win7 winxp osx
Re: Firewall The Physical NIC for all Virtual NICs
Yes, but is there a way to guarantee a user cannot bypass the host's firewall by creating
a bridged connection in a guest ?
Regards,
S.Mellz
a bridged connection in a guest ?
Regards,
S.Mellz
-
mpack
- Site Moderator
- Posts: 39134
- Joined: 4. Sep 2008, 17:09
- Primary OS: MS Windows 10
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Mostly XP
Re: Firewall The Physical NIC for all Virtual NICs
You want to prevent users of the host PC from using all of VirtualBox's capabilities? Apart from deleting (or not installing) the VBox bridge driver on the host I don't know any way to do that. I also am not clear on what threat you think this prevents.
-
BillG
- Volunteer
- Posts: 5106
- Joined: 19. Sep 2009, 04:44
- Primary OS: MS Windows 10
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Windows 10,7 and earlier
- Location: Sydney, Australia
Re: Firewall The Physical NIC for all Virtual NICs
You cannot create a bridged network in a guest unless you have access to the host OS to run the VirtualBox manager. Preventing that really has nothing to do with VirtualBox. It depends on the security settings in the host OS. I am not aware of any way you could prevent the user from changing the vm settings but do anything useful with the vm.
Bill
-
Smellz
- Posts: 35
- Joined: 6. Jul 2009, 12:42
- Primary OS: Debian other
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: debian mint win7 winxp osx
Re: Firewall The Physical NIC for all Virtual NICs
Thanks mpac, billg.
Do I understand you correctly ? ...
1. The ability for success of a global firewall policy for the Physical NIC is dependent on the Host, not Virtualbox.
2. If I am able to successfully apply a Global Firewall Policy to the Host's eth0, it will also apply to any Virtual Bridged NICs.
3. There is no way to prevent a non-root user from changing the virtual NIC from a NAT to Bridged.
I'm attempting to prevent direct access to the Internet from any existing Virtualbox Bridged machines,
the Host's eth0 is forced to access only via ssh proxy.
Thank you both.
S.Mellz
Do I understand you correctly ? ...
1. The ability for success of a global firewall policy for the Physical NIC is dependent on the Host, not Virtualbox.
2. If I am able to successfully apply a Global Firewall Policy to the Host's eth0, it will also apply to any Virtual Bridged NICs.
3. There is no way to prevent a non-root user from changing the virtual NIC from a NAT to Bridged.
I'm attempting to prevent direct access to the Internet from any existing Virtualbox Bridged machines,
the Host's eth0 is forced to access only via ssh proxy.
Thank you both.
S.Mellz