<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about SpoofGuard and multiple IP in vCloud Networking and Security Discussions</title>
    <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652206#M2333</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am agree there are some serious limiations of spoof guard in vCNS, not posssible to approve secondary addresses&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 May 2016 23:28:18 GMT</pubDate>
    <dc:creator>virtech</dc:creator>
    <dc:date>2016-05-25T23:28:18Z</dc:date>
    <item>
      <title>Question about SpoofGuard and multiple IP</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652202#M2329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I've some Linux machine that historically have some interface alias configured so I have an eth0 and eth0:1, eth0:2 configured with different IP Address.&lt;/P&gt;&lt;P&gt;Going on to do an initial approval of IP Address on SpoofGuard I saw that I don't see those aliases on the interface so I think they will not work.&lt;/P&gt;&lt;P&gt;Is this normal or there's some way to "approve" multiple address on a single physical interface?&lt;/P&gt;&lt;P&gt;I'm using vShield App 5.1.2a&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 18:55:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652202#M2329</guid>
      <dc:creator>fduranti</dc:creator>
      <dc:date>2013-06-18T18:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SpoofGuard and multiple IP</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652203#M2330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SpoofGuard feature seems pretty dumb to me, to be blunt. It seems to rely on what the VMware tools report and shuts down the port if it detects a different IP bound on the NIC. It can be easily bypassed by simply not binding the other IP to an interface, for example SpoofGuard will not block generated packets from &lt;EM&gt;"hping2 --spoof ba.d.i.p".&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;
&lt;P&gt;Going on to do an initial approval of IP Address on SpoofGuard I saw that I don't see those aliases on the interface so I think they will not work.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;&lt;P&gt;I haven't tested it myself, but if it doesn't detect your interface aliases as new IPs, then I assume it won't see any reason to block anything and just work "out of the box". Whether this behavior is really intended or satisfactory is another question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 19:57:36 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652203#M2330</guid>
      <dc:creator>MKguy</dc:creator>
      <dc:date>2013-06-18T19:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SpoofGuard and multiple IP</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652204#M2331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , Does spoofguard in vshield 5.5 support approval of&amp;nbsp; IPaddress aliases eth0:1, eth0:2 configured, so that traffic is allowed from the alias ipaddresses also?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Apr 2014 09:35:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652204#M2331</guid>
      <dc:creator>p_sudheer</dc:creator>
      <dc:date>2014-04-30T09:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SpoofGuard and multiple IP</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652205#M2332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems not be possible to set (approve) more than one ip to one mac.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in NSX it's possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Oct 2014 21:25:58 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652205#M2332</guid>
      <dc:creator>yonish</dc:creator>
      <dc:date>2014-10-05T21:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SpoofGuard and multiple IP</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652206#M2333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am agree there are some serious limiations of spoof guard in vCNS, not posssible to approve secondary addresses&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 May 2016 23:28:18 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/Question-about-SpoofGuard-and-multiple-IP/m-p/2652206#M2333</guid>
      <dc:creator>virtech</dc:creator>
      <dc:date>2016-05-25T23:28:18Z</dc:date>
    </item>
  </channel>
</rss>

