2.0

Table Of Contents
VMware Server User’s Guide
232 VMware, Inc.
Avoiding IP Packet Leakage in a Host-Only Network
Bydesign,eachhostonlynetworkshouldbeconfinedtothehostmachineonwhichit
issetup.Thatis,nopacketssentbyvirtualmachinesonthisnetworkshouldleakout
toaphysicalnetworkattachedtothehost.Packetleakagecanoccuronlyifamachine
activelyforwards
packets.Itispossibleforthehostmachineoranyvirtualmachine
runningonthehostonlynetworktobeconfiguredinawaythatpermitspacket
leakage.
Windows Hosts
SystemsusingserverversionsofWindows2000arecapableofforwardingIPpackets
thatarenotaddressedtothem.Bydefault,however,thesesystemscomewithIPpacket
forwardingdisabled.
IfyoufindpacketsleakingoutofahostonlynetworkonaWindows2000host
computer,checktoseewhether
forwardinghasbeenenabledonthehostmachine.Ifit
isenabled,disableit.
Table 11-1. Address Use on a Host-Only Network
Range Address Use Example
<net>.1 Hostmachine 192.168.0.1
<net>.2–<net>.127 Staticaddresses 192.168.0.2–192.168.0.127
<net>.128–<net>.253 DHCPassigned 192.168.0.128–192.168.0.253
<net>.254 DHCPserver 192.168.0.254
<net>.255 Broadcasting 192.168.0.255
Table 11-2. Address Use on a NAT Network
Range Address Use Example
<net>.1 Hostmachine 192.168.0.1
<net>.2 NATdevice 192.168.0.2
<net>.3–<net>.127 Staticaddresses 192.168.0.3–192.168.0.127
<net>.128–<net>.253 DHCPassigned 192.168.0.128–192.168.0.253
<net>.254 DHCPserver 192.168.0.254
<net>.255 Broadcasting 192.168.0.255