Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[求助/Help] 开出的 虚拟机可以访问 宿主机的网络, 请问有什么办法可以让虚拟机无法访问宿主机的网络? #20244

Open
khw934 opened this issue May 11, 2024 · 3 comments
Labels
question Further information is requested state/awaiting user feedback

Comments

@khw934
Copy link

khw934 commented May 11, 2024

开出的 虚拟机可以访问 宿主机的网络, 请问有什么办法可以让虚拟机无法访问宿主机的网络?

@khw934 khw934 added the question Further information is requested label May 11, 2024
@fangpsh
Copy link

fangpsh commented May 13, 2024

自定义一个安全组。

@DSYZayn
Copy link

DSYZayn commented May 16, 2024

@fangpsh 请教一下具体该怎么设置。我希望vpc内的虚拟机(172.16.0.0/24)不能访问宿主机所在的网段(192.168.1.0/24),尝试自定义安全组把出口流量的192.168.1.0/24网段禁止,导致虚拟机无法上网了。

@fangpsh
Copy link

fangpsh commented May 16, 2024

@fangpsh 请教一下具体该怎么设置。我希望vpc内的虚拟机(172.16.0.0/24)不能访问宿主机所在的网段(192.168.1.0/24),尝试自定义安全组把出口流量的192.168.1.0/24网段禁止,导致虚拟机无法上网了。

主动出,默认放行,drop 宿主机段,我这一切测试正常,符合预期。
主动入,默认拒绝,需要显式放行。

不过我的网络是经典网络(二层),非 VPC 网络,不知是否这里有差异。

https://www.cloudpods.org/docs/guides/onpremise/network/examples#%E4%BA%8C%E5%B1%82%E7%BD%91%E7%BB%9C%E9%85%8D%E7%BD%AE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested state/awaiting user feedback
Projects
None yet
Development

No branches or pull requests

3 participants