XEN Bridges with Debian
Ich verwende die folgende Netzwerkkonfiguration mit XEN:
- br0intern -> internal LAN (GREEN)
- br1extern -> WAN (RED) -> not used !!
- br2dmz -> DMZ (ORANGE)
- br3wlan -> WLAN (BLUE)
- br4off -> no network connection
Nur die interne Bridge (br0intern) wird direkt mit einer Netzwerkkarte (eth0) verbunden und mit einer IP-Adresse versehen.
Die XEN-Bridges (br2dmz, br3wlan) haben initial keine eigenen Verbindungen. Eine XEN-Bridge (br4off) bekommt nie eine Verbindung.
Die externe Bridge (br1extern) wird nur konfiguriert aber nicht gestartet, da die Firewall direkt eth2 verwendet und keine Bridge benötigt.
File: /etc/network/interfaces.d/xenbridges
# interfaces(5) file used by ifup(8) and ifdown(8) # Included from /etc/network/interfaces # --------------------------------- # settings for all XEN bridges # --------------------------------- iface xenbridge inet manual pre-up brctl addbr $IFACE bridge_fd 0 bridge_stp off bridge_hello 1 bridge_maxwait 0 bridge_waitport 0 post-up ip link set $IFACE promisc off post-down brctl delbr $IFACE # --------------------------------- # br0intern # eth0 -> intern, the internal lan # 192.168.2.5 # --------------------------------- iface br0intern inet static inherits xenbridge address 192.168.2.5/24 gateway 192.168.2.12 bridge_ports eth0 # --------------------------------- # br1extern # eth1 -> extern, the internet/router # not used (firewall uses physical device) # --------------------------------- iface br1extern inet manual inherits xenbridge # bridge_ports eth1 # --------------------------------- # br2dmz # none -> dmz, firewall-zone only # --------------------------------- iface br2dmz inet manual inherits xenbridge # --------------------------------- # br3wlan # wlan -> eth3 or firewall-zone # --------------------------------- iface br3wlan inet manual inherits xenbridge # bridge_ports eth3 # --------------------------------- # br4off # none -> offline zone # --------------------------------- iface br4off inet manual inherits xenbridge