1
General Discussion / Noob OPNsense question on virtualization
« on: July 15, 2019, 12:40:28 pm »
Hello,
I am about to install OPNsense as guest on headless host (Debian Buster/KVM)
I would like to make sure that the host will be isolated from the internet, but i don't really understand how it could be possible. I could "deny" the WAN network interface but if i do so, how the guest could have access to the internet?
The second option would be to "route" all internet traffic to the OPNsense guest first and then to the host and to my machines on the LAN.
But again, i think i do not get everything. I made lot of researches here and on google, but i do not find anything that could tell me how to parameter such a configuration ?
How did you manage to have a secures host for the internet ?
My second question is : As the host is headless and is installed on a dedicated machine without monitor.
Is there any "simple" web-based interface to install on the host so that i could administer all the virtualization stuff remotely ? I was thinking of oVirt but it appears to be experimental for Debian.
Thanks a lot for your help
I am about to install OPNsense as guest on headless host (Debian Buster/KVM)
I would like to make sure that the host will be isolated from the internet, but i don't really understand how it could be possible. I could "deny" the WAN network interface but if i do so, how the guest could have access to the internet?
The second option would be to "route" all internet traffic to the OPNsense guest first and then to the host and to my machines on the LAN.
But again, i think i do not get everything. I made lot of researches here and on google, but i do not find anything that could tell me how to parameter such a configuration ?
How did you manage to have a secures host for the internet ?
My second question is : As the host is headless and is installed on a dedicated machine without monitor.
Is there any "simple" web-based interface to install on the host so that i could administer all the virtualization stuff remotely ? I was thinking of oVirt but it appears to be experimental for Debian.
Thanks a lot for your help

