Re: Bringing up a guest with network disabled

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 10/01/2013 06:04 AM, James Gibbon wrote:
> 
> 
> Hello all,
> 
> I have a KVM guest VM which is a clone of a production machine
> running on a different physical server, incarnated from an 
> image backup.

Careful.  You need to scrub more than just the IP address for a clone
and it's parent to safely run at the same time.  For example, if you
don't scrub the entropy pool, then one of the two machines will now have
predictable "random" numbers just by watching what the other host did,
which is horrible from a security perspective.  I highly recommend the
use of 'virt-sysprep' on the image backup prior to creating your clone,
which will not only scrub the IP address, but everything else that ought
to be unique between a clone that is intended to run alongside the
parent.  Once you start from a clean image, then the question about
starting the guest with network disabled may be moot.

-- 
Eric Blake   eblake redhat com    +1-919-301-3266
Libvirt virtualization library http://libvirt.org

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
libvirt-users mailing list
libvirt-users@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libvirt-users

[Index of Archives]     [Virt Tools]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]

  Powered by Linux