linux:apps:kvm:client-ipv6
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| linux:apps:kvm:client-ipv6 [2026/09/16 13:55] – oscar | linux:apps:kvm:client-ipv6 [2026/09/16 14:02] (current) – oscar | ||
|---|---|---|---|
| Line 149: | Line 149: | ||
| To include strict anti-spoofing protection for both IPv4 and IPv6, you should replace < | To include strict anti-spoofing protection for both IPv4 and IPv6, you should replace < | ||
| + | #### Important Requirement: | ||
| If you require strict IPv6 source filtering, you must define the < | If you require strict IPv6 source filtering, you must define the < | ||
| + | The no-ipv6-spoofing filter requires libvirt to know exactly which IPv6 address belongs to the virtual machine. Unlike IPv4 (where libvirt can automatically learn the IP via DHCP snooping), you must explicitly pass the allowed IPv6 address as a parameter inside your VM's XML configuration. Update your VM interface via virsh edit Debian13-ESP32-ARMHF to look like this: | ||
| Here is exactly how your / | Here is exactly how your / | ||
| ```xml | ```xml | ||
| - | <filter name=' | ||
| - | < | ||
| - | < | ||
| - | </ | ||
| - | ``` | ||
| - | #### Important Requirement: | ||
| - | The no-ipv6-spoofing filter requires libvirt to know exactly which IPv6 address belongs to the virtual machine. Unlike IPv4 (where libvirt can automatically learn the IP via DHCP snooping), you must explicitly pass the allowed IPv6 address as a parameter inside your VM's XML configuration. | ||
| - | Update your VM interface via virsh edit Debian13-ESP32-ARMHF to look like this: | ||
| - | |||
| < | < | ||
| <mac address=' | <mac address=' | ||
| Line 167: | Line 160: | ||
| <model type=' | <model type=' | ||
| < | < | ||
| - | <!-- Replace with the actual IPv6 address assigned to this VM --> | + | <!-- Replace with the actual |
| + | < | ||
| < | < | ||
| </ | </ | ||
| <address type=' | <address type=' | ||
| </ | </ | ||
| + | </ | ||
| + | ``` | ||
| #### How this functions at the host level: | #### How this functions at the host level: | ||
| - | |||
| * clean-traffic builds filters to block any IPv4 or MAC spoofing attempts. | * clean-traffic builds filters to block any IPv4 or MAC spoofing attempts. | ||
| * no-ipv6-spoofing builds filters that drop any outgoing IPv6 packets whose source address does not match the exact IPV6 parameter value you provided. | * no-ipv6-spoofing builds filters that drop any outgoing IPv6 packets whose source address does not match the exact IPV6 parameter value you provided. | ||
| - | Would you like to know how to specify multiple IPv6 addresses if your VM uses both a global unicast address | + | ## Links |
| - | + | [1] (https:// | |
| - | + | [2] (https:// | |
| + | [3] (https:// | ||
linux/apps/kvm/client-ipv6.1789566941.txt.gz · Last modified: by oscar
