LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud
User Name
Password
Linux - Virtualization and Cloud This forum is for the discussion of all topics relating to Linux Virtualization and Linux Cloud platforms. Xen, KVM, OpenVZ, VirtualBox, VMware, Linux-VServer and all other Linux Virtualization platforms are welcome. OpenStack, CloudStack, ownCloud, Cloud Foundry, Eucalyptus, Nimbus, OpenNebula and all other Linux Cloud platforms are welcome. Note that questions relating solely to non-Linux OS's should be asked in the General forum.

Notices


Reply
  Search this Thread
Old 12-27-2010, 10:44 AM   #1
foyonoro
LQ Newbie
 
Registered: Dec 2010
Distribution: Ubuntu
Posts: 21

Rep: Reputation: 0
I have questions concerning running a host behind a firewall on a VM on the same PC


I've been wanting to run a firewall such as pfsense or m0n0wall in a virtual machine on my PC and have my PC (host) be firewalled and possibly NAT'ed behind it. This will work as my primary firewall since I don't have a router at the moment and will be a 2nd layer of defense as well as a 2nd nat layer afterwards (i know that's unnecessary).

Is this as safe as having the firewall on separate hardware? What extra dangers, if any, do you face running it on the same system? Lastly, can you use a guest firewall such as this for other systems if you have a 2nd network card on the PC?

Thanks.
 
Old 12-27-2010, 12:58 PM   #2
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Real hardware firewalls/routers, at least newer ones, are created and designed to "fail closed" which means that if someone does DoS it, or break it some other way, it will stop working all together.

This means that you wont have internet connectivity, but at least they can't get in, at that time, either.

If you use a regular piece of hardware, like a server, and a software firewall, your results may vary on this front. Perhaps someone overflows your NIC and gains access to your entire server and network... rather than getting locked out.
 
1 members found this post helpful.
Old 12-27-2010, 04:00 PM   #3
foyonoro
LQ Newbie
 
Registered: Dec 2010
Distribution: Ubuntu
Posts: 21

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by szboardstretcher View Post
Real hardware firewalls/routers, at least newer ones, are created and designed to "fail closed" which means that if someone does DoS it, or break it some other way, it will stop working all together.

This means that you wont have internet connectivity, but at least they can't get in, at that time, either.

If you use a regular piece of hardware, like a server, and a software firewall, your results may vary on this front. Perhaps someone overflows your NIC and gains access to your entire server and network... rather than getting locked out.
Thanks.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
No route to host - no firewall Ghodmode Linux - Networking 1 04-19-2007 10:01 AM
firewall rule or host.allow Super7 Linux - Security 2 08-09-2006 04:58 PM
connecting a host to internet thru another host (both running suse9.3) rcbell Linux - Networking 1 12-17-2005 05:35 PM
Can't host server with firewall, but can with router, could use help please calimer Linux - Software 2 03-01-2005 09:15 PM
Firewall (Single Host) R4z0r Linux - Security 4 10-24-2004 03:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud

All times are GMT -5. The time now is 03:40 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration