Linode Forum Index Linode Forum
Linode Community Forums
 


eth1 interface on private vlan visible only to own account

Click here to go to the original topic

 
       Linode Forum Index -> Feature Request/Bug Report
Author Message
TeddyR42



Joined: 30 Jan 2012
Posts: 16
Location: Glendale, CA

Posted: Mon Jan 30, 2012 6:46 pm    Post subject: eth1 interface on private vlan visible only to own account  

The ability to have eth1 interface on a private vlan only for the linodes under your own account to use for internal traffic.

This would allow more secure frontend/backend communications or testing without too much exposure (even with firewall rules setup) it would be one additional useful feature. This would also make NFS mounts more secure if needed.

I know that a private ip address can already be requested, but that address is on the same interface as the rest of the datacenter (eth0) and can be seen by any other linode at your datacenter.
Back to top  
jebblue



Joined: 23 May 2010
Posts: 112

Posted: Mon Jan 30, 2012 6:59 pm    Post subject:  

You might be able to do what you want with an alias if you are using a static ip already:

/etc/network/interfaces

auto eth0:1
iface eth0:1 inet static
address 127.0.0.100
netmask 255.255.255.0
#gateway
Back to top  
TeddyR42



Joined: 30 Jan 2012
Posts: 16
Location: Glendale, CA

Posted: Mon Jan 30, 2012 7:31 pm    Post subject:  

jebblue wrote: You might be able to do what you want with an alias if you are using a static ip already:
That would not work for what I am requesting.. :-(.

- 127.x.x.x is reserved for the local machine only and MUST not traverse outside the machine it is running on.

- I would want to have the two (or more) linodes communicate with each other, but not have other machines that are not on my account be able to see them at all

- I dont want to "pick an ip out the air" on a vlan shared by other users. Can you say "Anarchy!" [or headache troubleshooting an ip conflict or other problem caused by a misconfiguration on your part or on someone else selecting the same network range as you]....
Back to top  
Guspaz



Joined: 26 May 2009
Posts: 1150
Location: Montreal, QC

Posted: Tue Jan 31, 2012 10:17 am    Post subject:  

Firewall rules are good enough; nobody else can see your non-broadcast traffic, and you can prevent broadcast traffic with firewall rules. Adding a VLAN wouldn't make it any more secure. If you need more security, there's OpenVPN or the like.
Back to top  
jebblue



Joined: 23 May 2010
Posts: 112

Posted: Tue Jan 31, 2012 12:51 pm    Post subject:  

TeddyR42 wrote: That would not work for what I am requesting.. :-(.
I see, I misunderstood what you were asking for.
Back to top  
 
       Linode Forum Index -> Feature Request/Bug Report
Page 1 of 1