[Simh] C9.io

Jordi Guillaumes Pons jg at jordi.guillaumes.name
Fri Dec 1 20:53:22 EST 2017



> On 1 Dec 2017, at 23:26, Timothe Litt <litt at ieee.org> wrote:
> 
> 
> On 01-Dec-17 17:07, Dan Gahlinger wrote:
>> a pi would do it.
>> and it's not opening it up
>> you open to just one port to just that pi
>> for just the pps
>> 
> Not quite that simple.  To expand on what I wrote previously: Typically, machines inside your router trust each other.  In that case, once on the Pi (or SimH guest), a user has access to anything else on your internal network, unless you setup the right firewalls on each of your other internal machines.  With a little care, it's not hard to setup a subnet for the Pi & emulated machines that everyone else can distrust.
> 
> E.g. You open an ssh port to your Pi.  A user who ssh's to that Pi now has a local address, and can ssh to your desktop - or browse for Windoze/NFS shares - or whatever.  So you need to adjust the firewall on your desktop to be very careful about what it permits from the Pi.  (And guests on the Pi.)


If you want to effectively isolate your bunch-of-simh-stuff you can use VDE for the networking, and _NOT_ connect the virtual switch to your real network. Then you have an island of machines that can talk between them but not to the outside world (not even their host). You can plug in different vde switches running on different machines and still keep that network isolated.

Of course, the only way to log onto the machines would be TELNETing to a simh “serial port” attached to a TCP port. But that’s all.

In case you need to connect the vde network to your real net you could set up momentarily an vde_plug or an vde_cryptocab while the “outside” access is closed. 

VDE provides a lot of flexibility. 

Oh, did I say klh10 can attach itself to VDE now? ;)


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.trailing-edge.com/pipermail/simh/attachments/20171202/0fe3c49f/attachment.html>


More information about the Simh mailing list