On Fri, Nov 23, 2007 at 04:02:46AM +0100, Stefan de Konink wrote:
> Is there a way to prevent hwaddr/mac address spoofing between DomU's?
I use ebtables alone to do this. I have the list of MAC addresses
and IP addresses for each domU in a database, and from that I build
an ebtables ruleset. ARP replies from a MAC that does not
correspond with its assigned IPs are dropped and logged.
Cheers,
Andy
signature.asc
Description: Digital signature
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
|