5 ms·
I use them for many things, but most recently I found myself using a VM to avoid installing tracking software (essentially malware) required by my employer. I d
by vinnymac 4y ago
I use them for many things, but most recently I found myself using a VM to avoid installing tracking software (essentially malware) required by my employer. I don't turn it on unless someone asks questions, and otherwise can go about my business without fear of being monitored.
- no-dr-onboard 4y agoJust a heads up, a lot of endpoint detection and response runs at the kernel level and can view network traffic if you’re running in bridged mode.
- vinnymac 4y agoI appreciate the heads up, but I specifically put this VM on hardware I don't use for anything else, just in case it has more access than it should. I also blocked as much outbound traffic as I could.
- drbawb 4y agoAre VLANs enough to mitigate this? As a concrete example let's say I have an interface on the host sitting on a trunk port receiving tagged traffic. It exposes two such VLANs as pseudo-devices "nic.10" and "nic.20" which are enslaved to "bridge10" and "bridge20" respectively. If I have a VM with a virtual NIC sitting on bridge10, the guest kernel shouldn't be able to see traffic on bridge20, right? (Assuming nothing above the guest is doing L2/L3 forwarding between the two VLANs.)
- jasomill 4y agoSure, as long as everything is configured correctly and you trust the network stack on the host connected to the trunk port. I use a similar configuration on my three ESXi hosts, with a pair of Ethernet ports on each host LACP bonded to a trunk port channel on the physical switch, a separate port group per VLAN on the virtual switches, and all L3 features disabled on the physical switch, so traffic only passes between VLANs through a dedicated router VM with strict firewall rules in place. Works great.