On Wed, Aug 22, 2018 at 07:41:36AM -0700, lite...@gmail.com wrote:
> Also I thought HVM implies that it is a VM that can be started from an ISO.
> https://www.qubes-os.org/doc/hvm/
> And the fact that I posted the link to the tutorial should make it easier to 
> understand what I want to do here: use Ubuntu as a netVM
> 
There's a difference between a qube running in HVM virt_mode, which is
what sys-net does, and a HVM as StandAlone.

There is a work round which you can try, which uses the Qubes
infrastructure.
Create a non networked firewall and attach the HVM to it.
This gives you a vif+ in the Ubuntu HVM.

Attach your qubes to the new firewall.
Change the routing and iptables on the new firewall to allow traffic
flows between the vif+ interfaces as appropriate.
Insert a new rule to forward DNS to your chosen server.

The advantage is this requires no configuration on the qube side, so you
can switch easily between different netvm egress points, by attaching to
different firewalls.
The native Qubes firewall tools work fine.

I do this to run OpenBSD as one of my netvms.

unman

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20180823141127.2i57irw34lg2ppk4%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to