Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - yannssolo

#1
Thanks for your answer.

I think i got it. When i read you i think it's not so related to kvm stuff but opnsese and nic topology.

If i bridge a physical nic to the wan interface of opnsense, it's enough to consider the host isolated ? is that what you mean ?
In that way, the host does not have any connection to the internet ?
That's what i want, the host should not be reachable from the exterior.

Actually i have (not received yet, it's stucked at customs:)) a 6 NIC mini-pc. I think i have to investigate how to deal with vSwitch.

Thanks






#2
Snif...nobody wants to help me :(
#3
Hello,

I am about to install OPNsense as guest on headless host (Debian Buster/KVM)

I would like to make sure that the host will be isolated from the internet, but i don't really understand how it could be possible. I could "deny" the WAN network interface but if i do so, how the guest could have access to the internet?

The second option would be to "route" all internet traffic to the OPNsense guest first and then to the host and to my machines on the LAN.

But again, i think i do not get everything. I made lot of researches here and on google, but i do not find anything that could tell me how to parameter such a configuration ?

How did you manage to have a secures host for the internet ?


My second question is : As the host is headless and is installed on a dedicated machine without monitor.
Is there any "simple" web-based interface to install on the host so that i could administer all the virtualization stuff remotely ? I was thinking of oVirt but it appears to be experimental for Debian.

Thanks a lot for your help


#4
Hello,

I would like to know how if it's possible to configure opnsense on a machine which has only one ethernet interface.
On that machine I also have one wifi interface.

So, is it possible (and how, if possible), to use the ethernet interface for the WAN and the wifi interface for the LAN, maybe by setting it up as wifi access point ?

I do not have any manage switch, so i can't do it with VLAN.

Thanks for your help.