Quantcast
Channel: VMware Communities: Message List
Viewing all articles
Browse latest Browse all 224018

Re: Question about SpoofGuard and multiple IP

$
0
0

The SpoofGuard feature seems pretty dumb to me, to be blunt. It seems to rely on what the VMware tools report and shuts down the port if it detects a different IP bound on the NIC. It can be easily bypassed by simply not binding the other IP to an interface, for example SpoofGuard will not block generated packets from "hping2 --spoof ba.d.i.p".

 

Going on to do an initial approval of IP Address on SpoofGuard I saw that I don't see those aliases on the interface so I think they will not work.

I haven't tested it myself, but if it doesn't detect your interface aliases as new IPs, then I assume it won't see any reason to block anything and just work "out of the box". Whether this behavior is really intended or satisfactory is another question.


Viewing all articles
Browse latest Browse all 224018

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>