Page 1 of 1

true isolation of XP host and guests?

Posted: 29. Sep 2012, 15:41
by Josephine
I know this has been talked about before, but I am uncertain of the settings required to isolate, as much as possible, my XP host from the various guests I use. I recently installed an additional NIC, as I read about here, and I have configured the properties of both cards in the following ways under the Network Connections of WinXP:

1) First of all, there are 3 LAN/ high speed internet connections shown: local area connection (LAC) #2, LAC #5, and VirtualBox Host- Only Network.

2) Right now, I am on the guest system. Both LAC 2&5 say "network cable unplugged" and "firewalled" while the Virtualbox host shows "connected" and "firewalled". I originally set up network connection properties in XP so that LAC #2 has "Client for Microsoft Networks", "QoS Packet Scheduler" and "Internet Protocol TCP/IP" enabled with the "Internet Connection Sharing" box unchecked; LAC #5 has "Client for Microsoft Networks", and "Internet Protocol TCP/IP" DISabled with the "Internet Connection Sharing" box unchecked and also has "Virtual Box Bridged Networking Driver" checked (this driver was UNchecked in LAC#2), and "QoS Packet Scheduler" remains the same (enabled). Finally, for the VirtualBox Host- Only Network, the connection properties are that ALL boxes are checked (Client, TCP/IP, QoS, and Virtualbox driver), but Internet Sharing remains unchecked. I have all VM's in Virtualbox set up in the "bridged adapter" configuration to card #2 with promiscuous mode "deny" and "cable connected" checked.

Performance: When connected as above and running a guest, the guest seems to be the only system that can access the Internet. When I remove the cable and plug into the other card, the opposite occurs- hosts accesses the net and the guest does not.

Of course, I *appear* to be achieving the desired results, but I wanted to post settings here for confirmation. Also, is the guest truly isolated from the host when accessing the net this way, or is there still a path?

Sorry to post the detailed settings, but I see very little of this in past posts so hoping to help others lacking settings information.

Thanks in advance for both your confirmation and help.

Josephine

Re: true isolation of XP host and guests?

Posted: 30. Sep 2012, 08:49
by BillG
Since the vm can only connect to a physical network through some physical device on the host, there must be some connection. All that you can do is minimise the contact (if this worries you).

If you disable the TCP/IP connection of a NIC to a particular OS you have blocked all common internet protocols from using it. That is about as much as you can realistically do.

If you are not using the host only connection, you can disable it from the host OS. (In fact, VirtualBox gives you the option to not install it when you install VB).

Here is a link to a screenshot on my skydrive showing the NIC properties of my two NICs. LAC2 is dedicated to the host and LAC3 to the vms. The host is Windows 7.
https://skydrive.live.com/#cid=B71C970B ... B3C7%21390

Re: true isolation of XP host and guests?

Posted: 30. Sep 2012, 18:27
by Josephine
Thanks for the reply. I especially appreciate the screenshots as a pic says a thousand words. I would have posted that originally, but I don't have a pg to take the shots.

One thing I'm wondering about. You say the host only connection is not needed. I was under the impression that it was necessary for the VM to connect to the net. If not, then I will delete or disable it, but what is it for?

Thanks,
Josephine

Re: true isolation of XP host and guests?

Posted: 1. Oct 2012, 02:08
by BillG
The host only connection is an interface on the host to which a vm can connect. It is only essential for host-guest connection if the host does not have any other network connection.

If you are not using it for host-guest connection you can disable it (or not install it). I never install it in a host when I install VirtualBox because I never use it.