Solved

Can i create a route by MAC address to keep a machine limited to an ip address

Posted on 2011-03-14
4
370 Views
Last Modified: 2012-05-11
I have a server hosting two virtual machines.  Each machine is assigned a static IP address in a different network and is routed to a separate firewall gateway. they both travel through a common virtual switch, and through a physical switch as well before the gateway.
  Since these are two different entities i am concerned that a user on network1 could find out the address of network2. Since they both use WAN access, they cannot remove the existing IP without losing their connection, but adding an ip could be an issue if via social hacking, sniffing or dumb luck, they discovered the other address range. In that case they would be able to add that IP range on their machine and browse to the other network. I realize they would likely have to crack a password to actually break in another machine, but if they are doing the first then they would likely do the second as well. So, if network1 is 192.168.11.0/24 and network2 is 192.168.12.0/24 for instance, can i use the computer MAC address on the machines in a route to block all traffic from one VM to the other VM. Or set up a route on each machine that automatically sent any traffic not on their correct network to the bit bucket.  What is the most effective way to limit the machines to their own networks?
0
Comment
Question by:timgil
  • 3
4 Comments
 
LVL 6

Expert Comment

by:RKinsp
Comment Utility
If i understand your problem correctly, Access Control Lists are the best way to limit this.

Since your VMs are on different VLANs, you can implement this security on your Router by blocking communication from 192.168.11.0 to 192.168.12.0 and vice-versa.

What router are you using?

-RK
0
 

Author Comment

by:timgil
Comment Utility
I have a fortinet 111c router, but my concern is that the packets would never go that far, if say the guy on network one set an additional IP address and gateway valid on the second network he could browse that network. the packets might only have to go as far as the first switch?  I dont know for sure about that, i am asking. As far as the ACL's go, They have administrator level access on each of their respective machines, I would not be able to set an ACL that they couldn't undo.
0
 
LVL 6

Accepted Solution

by:
RKinsp earned 250 total points
Comment Utility
Your physical switch could limit this if it has layer 2 ACL (which external users should not have access to), the problem is the Virtual Switch. If it is the regular vSwitch then you can't block the traffic from virtual machine A to virtual machine B.

What you would have to do is bridge the virtual nics to the physical instead of using a virtual switch so all traffic would have to go out to the physical switch. If it supports Layer 2 ACLs you could use that to block communication from MAC A to MAC B. It might not even be necessary since a lot of switches will not forward a packet to the interface it came from, but it would be a way to make sure.

Although this would stop some users, please note that it is possible to change MAC addresses on a virtual machine. You could use something more advanced for a virtual IPS (check out vcontroller on google).

-RK
0
 
LVL 6

Expert Comment

by:RKinsp
Comment Utility
Thanks for the points!

-RK
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now