Saturday, September 28, 2024

Re: Firewall for isolated hosts

On 2024-09-28, Nicolas Goy <me@kuon.ch> wrote:
> On Fri Sep 27, 2024 at 5:45 AM CEST, David Gwynne wrote:
>>
>> using a /32 on each host with a single shared gateway ip for the
>> subnet should work too. the config on the protected host side sounded
>> fiddly though, especially if you have multiple hosts on promisc or
>> community ports on the pvlan that you want to be accessible without
>> going via the router.
>
> I looked at different datacenter hosting, (OVH in france, Hetzner in germany)
> and they all do this.

I don't know how the upstream side is configured, it would be
interesting to know.

On the client side, typically they advise running DHCP and it "just
works" with most OS. (OpenBSD added this to dhclient in Dec 2013).

Alternatively for manual config, on OpenBSD it's something like

route add $gateway -cloning -link -iface $iface
route add default $gateway

Some Linux examples at
https://docs.hetzner.com/robot/dedicated-server/network/net-config-debian-ubuntu/

--
Please keep replies on the mailing list.

No comments:

Post a Comment