Mailinglist Archive: opensuse-security (685 mails)

< Previous Next >
VMWare through SuSEFirewall2
  • From: Pep Serrano <pep@xxxxxxxxxxx>
  • Date: Sun, 24 Feb 2002 18:21:19 +0100
  • Message-id: <20020224171809.0736BE653B@xxxxxxxxxxxx>
I have SuSEFirewall2 running in my laptop to drop every incoming connection
but ssh and http. Last week I installed VMWare with both host-only and
bridged network configurations.
So now I have two new network devices. This is output from ifconfig:

vmnet1 Link encap:Ethernet HWaddr 00:50:56:C0:00:01
inet addr:172.16.134.1 Bcast:172.16.134.255 Mask:255.255.255.0
inet6 addr: fe80::250:56ff:fec0:1/10 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:111 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)

vmnet8 Link encap:Ethernet HWaddr 00:50:56:C0:00:08
inet addr:172.16.144.1 Bcast:172.16.144.255 Mask:255.255.255.0
inet6 addr: fe80::250:56ff:fec0:8/10 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:4 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)

The firewall doesn't know about the new interfaces... and so it complains:

Feb 24 17:48:42 petit kernel: SuSE-FW-DROP-ANTI-SPOOFINGIN=vmnet1 OUT= MAC=
SRC=172.16.134.1 DST=172.16.134.255 LEN=240 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=138 DPT=138 LEN=220


I already tried to set both interfaces in the firewall config to be my
internal interfaces: FW_DEV_INT="vmnet1 vmnet8".

But when the FW loads the rules at boot time VMWare is not started yet and
interfaces vmnet1 and vmnet8 do not exist. I get the following error:

Starting Firewall Initialization: (phase 2 of 3) modprobe:
modprobe: modprobe: Can't locate module vmnet1
modprobe: modprobe: Can't locate module vmnet8
failed


So, how do you configure your virtual NICs to go through the firewall???

< Previous Next >
This Thread
  • No further messages