User Tools

Site Tools


linux:apps:kvm:client-ipv6

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
linux:apps:kvm:client-ipv6 [2026/09/15 21:16] – oscarlinux:apps:kvm:client-ipv6 [2026/09/16 14:02] (current) – oscar
Line 73: Line 73:
 These network filters define the nft firewall setting that the host apply on the virbr0 bridge interface.  These network filters define the nft firewall setting that the host apply on the virbr0 bridge interface. 
    
-The `clean-traffic` filter is designed to prevent IP/MAC spoofing by only allowing IPv4 traffic matching the VM's assigned IP address. To use IPv6 without removing this security filter, you must explicitly chain or include the `allow-ipv6` sub-filter.+The `clean-traffic` filter is designed to prevent IP/MAC spoofing by only allowing IPv4 traffic matching the VM's assigned IP address. 
  
-Here is how to properly configure it.+### Allow IPv6 Filter 
 +To use IPv6 without removing this security filter, you must explicitly chain or include the `allow-ipv6` sub-filter. Here is how to properly configure it.
  
 #### Step 1: Ensure the Filter Configurations Exist #### Step 1: Ensure the Filter Configurations Exist
Line 141: Line 142:
 # virsh start your-vm-name # virsh start your-vm-name
 ``` ```
 +### IPv6 Spoofing Filter
  
- +If using the default allow-ipv6, keep in mind that it acts as an open pass for IPv6 traffic through that interface. If you want strict anti-spoofing for both IPv4 and IPv6 (instead of a blanket "allow all IPv6" via allow-ipv6), you can combine clean-traffic with specific IPv6 variables, or reference a custom filter. 
-#### Spoofing +
- +
-Alternative: Custom No-Spoofing Filter (Advanced) +
-If you want strict anti-spoofing for both IPv4 and IPv6 (instead of a blanket "allow all IPv6" via allow-ipv6),  +
-you can combine clean-traffic with specific IPv6 variables, or reference a custom filter. +
 [1] (https://github.com/fsinf/libvirt-fsinf) [1] (https://github.com/fsinf/libvirt-fsinf)
  
-If using the default allow-ipv6, keep in mind that it acts as an open pass for IPv6 traffic through that interface.  +To include strict anti-spoofing protection for both IPv4 and IPv6, you should replace <filterref filter='allow-ipv6'/> with <filterref filter='no-ipv6-spoofing'/>. Do not keep allow-ipv6 in the file. The allow-ipv6 filter acts as a blanket permit for all IPv6 traffic, which would completely override and disable the security rules created by no-ipv6-spoofing.
-If you require strict IPv6 source filtering,  +
-you must define the <parameter name='IPV6' value='...'/> inside the <filterref> block using an anti-spoofing filter like no-ipv6-spoofing.  +
-[1] (https://libvirt.org/formatnwfilter.html), [2] (https://github.com/fsinf/libvirt-fsinf)+
  
 +#### Important Requirement: Passing the IPv6 Parameter
 +If you require strict IPv6 source filtering, you must define the <parameter name='IPV6' value='...'/> inside the <filterref> block using an anti-spoofing filter like no-ipv6-spoofing. 
 +The no-ipv6-spoofing filter requires libvirt to know exactly which IPv6 address belongs to the virtual machine. Unlike IPv4 (where libvirt can automatically learn the IP via DHCP snooping), you must explicitly pass the allowed IPv6 address as a parameter inside your VM's XML configuration. Update your VM interface via virsh edit Debian13-ESP32-ARMHF to look like this:
  
- 
-To include strict anti-spoofing protection for both IPv4 and IPv6, you should replace <filterref filter='allow-ipv6'/> with <filterref filter='no-ipv6-spoofing'/>. 
-Do not keep allow-ipv6 in the file. The allow-ipv6 filter acts as a blanket permit for all IPv6 traffic, which would completely override and disable the security rules created by no-ipv6-spoofing. 
 Here is exactly how your /etc/libvirt/nwfilter/clean-traffic-ipv6.xml file should look: Here is exactly how your /etc/libvirt/nwfilter/clean-traffic-ipv6.xml file should look:
- +```xml
-<filter name='clean-traffic-ipv6' chain='root'> +
-  <filterref filter='clean-traffic'/> +
-  <filterref filter='no-ipv6-spoofing'/> +
-</filter> +
- +
-## Important Requirement: Passing the IPv6 Parameter +
-The no-ipv6-spoofing filter requires libvirt to know exactly which IPv6 address belongs to the virtual machine. Unlike IPv4 (where libvirt can automatically learn the IP via DHCP snooping), you must explicitly pass the allowed IPv6 address as a parameter inside your VM's XML configuration. +
-Update your VM interface via virsh edit Debian13-ESP32-ARMHF to look like this: +
 <interface type='network'> <interface type='network'>
   <mac address='52:54:00:7e:d3:ee'/>   <mac address='52:54:00:7e:d3:ee'/>
Line 175: Line 160:
   <model type='virtio'/>   <model type='virtio'/>
   <filterref filter='clean-traffic-ipv6'>   <filterref filter='clean-traffic-ipv6'>
-    <!-- Replace with the actual IPv6 address assigned to this VM -->+    <!-- Replace with the actual IPv4 + IPv6 address assigned to this VM --> 
 +    <parameter name='IP' value='129.97.134.3'/>
     <parameter name='IPV6' value='2001:db8:1::50'/>     <parameter name='IPV6' value='2001:db8:1::50'/>
   </filterref>   </filterref>
   <address type='pci' domain='0x0000' bus='0x01' slot='0x00' function='0x0'/>   <address type='pci' domain='0x0000' bus='0x01' slot='0x00' function='0x0'/>
 </interface> </interface>
 +</filter>
 +```
  
-## How this functions at the host level: +#### How this functions at the host level:
 * clean-traffic builds filters to block any IPv4 or MAC spoofing attempts. * clean-traffic builds filters to block any IPv4 or MAC spoofing attempts.
 * no-ipv6-spoofing builds filters that drop any outgoing IPv6 packets whose source address does not match the exact IPV6 parameter value you provided. * no-ipv6-spoofing builds filters that drop any outgoing IPv6 packets whose source address does not match the exact IPV6 parameter value you provided.
  
-Would you like to know how to specify multiple IPv6 addresses if your VM uses both a global unicast address (GUA) and a link-local address, or are you assigning a single static address? +## Links 
- +[1] (https://github.com/fsinf/libvirt-fsinf) \\ 
- +[2] (https://wiki.csclub.uwaterloo.ca/KVM) \\ 
 +[3] (https://cubepath.com/docs/virtualization-vps/virtual-network-configuration-with-libvirt) \\
  
linux/apps/kvm/client-ipv6.1789506999.txt.gz · Last modified: by oscar