Hello Craig,

 

I’ve never done that, but wouldn’t VLANs (on the network side) be a good solution for your problem?

Toasters work perfectly well with VLANs. If the physical interface is a 802.1q (VLAN trunk) port, the physical filer doesn’t have an ip address directly on this physical interface.

Instead, there are virtual interfaces which do have IP addresses and your v-filer0 would also hae an 802.1q port as the „uplink“ port but it would have different VLANs configured than the physical filer.

 

Would that be a way to go for you?

 

Bye,

Alex

 

Von: toasters-bounces@teaparty.net [mailto:toasters-bounces@teaparty.net] Im Auftrag von Craig A. Falls
Gesendet: Donnerstag, 19. Jänner 2012 21:07
An: toasters@teaparty.net
Betreff: v-filers and external network isolation

 

Good People, I am a long time reader, novice poster, and I have a question for you.

 

I have a environment where I want to put a single physical filer across two distinct networks (one internal and once external).  Using v-filers I want to provide services for both networks.  Generally I would use two physical filers for this, so attacks on the physical filer in the external network would only compromise storage in the external network.

 

In using a single physical filer, and using v-filers, I am hoping to achieve the same results, the issue is however that I can still get to v-filer0, and thus the filer as a whole from the IP address on the interface that is hosting the v-filers provisioned to the external network.  Thus providing an attack vector to something that before (with two physical filers) was completely inaccessible.

 

I see two possible solutions that I am not sure are implementable:

 

(1) Somehow creating the interface connected to the external network without an IP address, thus v-filers would have IP address on that interface, and be accessible, but the v-filer0 would not be accessible, as there is no IP to access it, or

 

(2) Somehow deny ssh to v-filer0 from the external network interface, but it would still have to work for the v-filers on that interface.

 

Not sure if these are possible, or an extensive list of the ways to achieve what I am attempting.  Also in re-reading this SSH isn't the only attach vector, http and any other management interface would have to be denied from the external interfaces as well.  Any advice or thoughts would be much appreciated.

 

thanks

c