• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Virtual Routers/Firewalls

nitrobass24

[H]ard|DCer of the Month - December 2009
2FA
Joined
Apr 7, 2006
Messages
10,477
So i have been thinking about virtualizing a pfsense or Astaro firewall for use on my Home network, but in the past here it seems that people always scream when they see you are virtualizing your firewall on the same box as production and i get it that there are possible vulnerabilities in the hypervisor that could be exploited because its just software and as we know, no software is 100% secure...but i would like to see some hard facts rather than theory.

Does anyone have anything they can point me too that would show why this is a bad idea or best practices for or against this type of configuration?
 
Main issue from a performance standpoint would be increased network latency (a graph of data use versus time would be rather spikey) because the firewall software isn't always running. If you're running any VoIP applications or the like, you might notice some call quality issues. Furthermore, I would recommend increasing the size of any packet buffers, because since the firewall software is not executing code all the time, you get a buildup of traffic between each execution cycle.
 
wasn't this discussed so many times ?

I think we all agreed it was a bad idea to virtualize your firewall, keep it on a dedicated box.
 
wasn't this discussed so many times ?

I think we all agreed it was a bad idea to virtualize your firewall, keep it on a dedicated box.

Not if you secure it properly. The only difference is people attacking from the inside, or doing MITM between the firewall and the internet on the vswitch for that. If you harden your ESXi box properly you don't have to worry about that. As far as exploits for ESXi allowing access to the firewall again I am not worried because there are an equal number of exploits for any stand alone firewall.

Personally I have had my pfSense running for a while now virtually, and have had multiple of my coworkers (all security guys) attack it from inside and outside, and they found that it was just as hardened as my physical pfSense box.
 
wasn't this discussed so many times ?

I think we all agreed it was a bad idea to virtualize your firewall, keep it on a dedicated box.

This response right here is why I started this thread.

I could not find where this topic was discussed in depth. Sure I agree the consensus is to not do it.

But why? What's the risk, bast practices, etc.that's what I'm (and I'm sure others) are looking for.
 
I personnel don't have a problem with it. It all depends how you've built out your public network and VLAN infrastructure.

Don't forget that most of the time you'll throw your Internet connection, that is public, down a segmented vlan (on your core switch), so you can add more than one device to it. Is there much of a difference between that and trunking a segregated vlan (at layer 2) to a Virtual Machine.

I'd like to hear some of the reason's behind the argument of it being bad?
 
Last edited:
I personnel don't have a problem with it. It all depends how you've built out your public network and VLAN infrastructure.

Don't forget that most of the time you'll though your Internet connection, that is public, down a segmented vlan (on your core switch), so you can add more than one device to it. Is there much of a difference between that and trunking a segregated vlan (at layer 2) to a Virtual Machine.

I'd like to here some of the reason's behind the argument of it being bad?

how about this one, your main machine fails and all your computers that relied on it for dhcp & dns are all down.

Keeping your firewall separate is the best practice.

I don't know of any businesses that run a firewall inside a vm on their server etc etc.
 
how about this one, your main machine fails and all your computers that relied on it for dhcp & dns are all down.

Keeping your firewall separate is the best practice.

I don't know of any businesses that run a firewall inside a vm on their server etc etc.

I think your getting mixed up with deployments, business needs and best practices.

This hole argument points to the fact that Virtualization is a bad thing. Did you consider HA or DRS? If your firewall is virtualized then it will be more redundant as you'll normally have more than one ESX host for redundancy. I'm not thinking ESXi and one host. If your thinking ESXi and one host, then don't you think that all your VMs failing would be a bigger problem than the Internet. Not to mention that most businesses run such network services such as DNS on there Domain Controllers, that under a single host would fail and from a users point of view therefore the Internet.

A lot of business needs would point to the fact of running independent firewall. I don't think people are discrediting that. I can also think of some situation where a business need would point to a Virtual Firewall as a good thing. For me its not a business need at this point because there are many variables. Also Best Practices would dictate redundancy, if the business need suite.

So for me IMO and IMO only its a question of security?
 
Sorry for going off track down a business case. I seem to have forgotten nitrobass24 is talking about Home use. For home use and if something fails you can always keep your old firewall/gateway/router around, just in case.

But I do have a question. Why do you want to virtualize your firewall? Is it just a test, trial and just because thing?
 
It is actually cheaper to do HA / failover if you virtualize your firewall, you also don't deal with downtime that comes with hardware firewalls. It is rare for one to die, but it does happen and over the last year I have replaced / RMAed more then 10. The only downside is that there are only a handful of Firewalls/Routers/UTMs with virtual appliance support. As the trend goes to everything virtual the big players are starting to hint at offering them (Both my Sonicwall and Juniper reps, along with our cymphonics guy have all mentioned we should see virtual appliances from them in the next year or so).

But as FlangeMonkey stated if my hypervisor is down my AD servers are down, my email is also probably down, my LOB apps are down, and my fileshares are down, so as an IT guy prioritizing disaster recovery I am more worried that I have to get my VMs back up then I am that people can't surf the internet mindlessly while they wait for it to get fixed. I would rather dump the extra $2k it would cost for a physical firewall and all the licensing at a second hypervisor and setup clustering.
 
Sorry for going off track down a business case. I seem to have forgotten nitrobass24 is talking about Home use. For home use and if something fails you can always keep your old firewall/gateway/router around, just in case.

But I do have a question. Why do you want to virtualize your firewall? Is it just a test, trial and just because thing?

Mostly cause I can.

But right now my firewall is a dlink 655 wifi router. I already have a hyper-v cluster setup at home so if I go virtual I have redundancy and I can run astaro or pfsense or something else.
 
Here's one: http://hardforum.com/showthread.php?t=1554608 (relevant post #31).

You're right, it's about hypervisor exploits (and possibly easier misconfiguration). If you can afford, definitely physically separate inside/outside servers. Or, alternatively, know all your eggs are in the same basket and understand the risk you're taking.

It's just like HA; it comes down to the question if it's worth it. Personally, I don't think it makes much difference for normal home use but only you know how highly you value it.

Edit: Looks like cisco already has virtual firewalls; http://www.cisco.com/en/US/docs/switches/datacenter/vsg/sw/4_2_1_VSG_1_1/release/notes/vsg_rn.html .
 
Last edited:
Here's one: http://hardforum.com/showthread.php?t=1554608 (relevant post #31).

You're right, it's about hypervisor exploits (and possibly easier misconfiguration). If you can afford, definitely physically separate inside/outside servers. Or, alternatively, know all your eggs are in the same basket and understand the risk you're taking.

It's just like HA; it comes down to the question if it's worth it. Personally, I don't think it makes much difference for normal home use but only you know how highly you value it.

I'd love more info on that, although I haven't read the hole thread. I'm finding it hard to see what they would attack or exploit. You'd normally segment the public network either through physical NIC's or vlans so they could only exploit or hit the VM not the hypervisor box or management VC. In fact thinking about it the only thing I can see vulnerable is the HAL as this is effectively management of the hardware and is the backplain.

From a business point of view this unknown might be the case for not virtualizing a firewall. Same goes for the case of... its a possibility... but I personally want more understanding, as I don't like going on general ideology that isn't backed up with a technical explanation.
 
Yup, unless there's some nasty bug in vswitch or the like, you first have to exploit VM. Thing is vswitch is rather low level and not that complex, so exploits on this level are rather unlikely.

What's problematic is, if you manage to get access to one VM, you get unrestricted access to all VMs with help of hypervisor exploits. With internet facing services on same physical box, chances of someone getting access to one VM are not insignificant. Also, hypervisor code for VM separation is much more complex with possible ways to get around it, which hypervisor has to watch out for. In other words, more likely to be exploitable.

That's why i don't think it's all that less secure if you run firewall + internal servers for home use on same box. Compromised firewall = game over.
 
Last edited:
A lot of the hypervisor exploits that people are mentioning are ones that are launched from the inside of the network. If someone is on the inside of your network you are already compromised, and the last thing you need to worry about is the fact that they got to your firewall.

From the outside my pfSense box looks like a pfSense box, and by using all standard sniffers I haven't been able to identify that it is running on ESXi. If someone were going to exploit my network they would go after one of my open ports and get in through there.

So basically you just need a dedicated NIC and vswitch for the WAN interface and you are good to go.
 
Main issue from a performance standpoint would be increased network latency (a graph of data use versus time would be rather spikey) because the firewall software isn't always running. If you're running any VoIP applications or the like, you might notice some call quality issues. Furthermore, I would recommend increasing the size of any packet buffers, because since the firewall software is not executing code all the time, you get a buildup of traffic between each execution cycle.

I had this exact same problem trying to run Untangle and pfSense in VM's on ESXi. Jitter, latency and dropouts went through the roof. Even removing one of those firewalls and leaving VMware to run a single virtual still had some problems, though not as bad.

Two physical boxes fixed everything. I do VoIP from home all the time.
 
I had this exact same problem trying to run Untangle and pfSense in VM's on ESXi. Jitter, latency and dropouts went through the roof. Even removing one of those firewalls and leaving VMware to run a single virtual still had some problems, though not as bad.

Two physical boxes fixed everything. I do VoIP from home all the time.

That's very odd because I have never had problems with my virtual appliances in ESX.
 
A lot of the hypervisor exploits that people are mentioning are ones that are launched from the inside of the network. If someone is on the inside of your network you are already compromised, and the last thing you need to worry about is the fact that they got to your firewall.

From the outside my pfSense box looks like a pfSense box, and by using all standard sniffers I haven't been able to identify that it is running on ESXi. If someone were going to exploit my network they would go after one of my open ports and get in through there.

So basically you just need a dedicated NIC and vswitch for the WAN interface and you are good to go.

What is exposed that the exploits are being used on? Does anybody have any blogs, documentation, or discussions on them?
 
This is like asking what parts of an internet service are exposed. Practically the whole hypervisor, though there might be another layer between VM specific and host part. I think you'll be hard pressed for any sufficiently detailed discussion without getting into gritty details of exploits themselves.
 
This is like asking what parts of an internet service are exposed. Practically the whole hypervisor, though there might be another layer between VM specific and host part. I think you'll be hard pressed for any sufficiently detailed discussion without getting into gritty details of exploits themselves.

No and Yes, I'm effectively asking what the exploits are targeting. I'm not sure what type of exploits that people are referring too as its all a little vague. I have found some information on one single exploit that is not moving from VM to VM, but stealing VM's based on a webserver traversal exploit. This has been patched by VMware, but this is usually mitigated by segmentation, which is usually best practices for all management web, ssh, etc.

I've also found information on a untrusted execution from within a VM, but I'm not sure what this exploit gives to parental threat.

There are a lot of points that people are hitting on that are good advice/info/things to think about, especially the common misconception that Visualization is bulletproof. However I'd also like to talk about the exploits themselves, but I'm not sure where this forum stands on discussing this type of security?
 
I don't think you should look at what's already been exploited because that should be patched now but what's possible to exploit and that could be more or less everything in hypervisor. Besides, hardware (processor) exploits are not impossible, google Rutkowska's SMM attacks.

Btw, I stumbled across http://advosys.ca/viewpoints/2006/04/virtualization-insecurity/ which is a good read.

Edit: For a taste, I remember reading about an exploit that could be used to access files on host OS.
 
Back
Top