Xen · Platform
Frabs for XCP-ng
On an XCP-ng host, Frabs lists the running domains and watches each VM's virtual interface.

XCP-ng
- Protects
- Xen virtual machines
- Recognised by
- The XCP-ng release
- Watches
- vif<domid>.<n>
- Panel links
- Not needed
How it works
How Frabs works on XCP-ng
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise XCP-ng
The XCP-ng release tells the sensor which platform it is on.
- 03
Find every guest
xl list for each running domain.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
vif<domid>.<n>
One per VM network device, for example vif12.0
Bridges. The bridges your VMs attach to. Bridges with no VMs are left alone.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on XCP-ng
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- Install on each XCP-ng host
- Read the Install Guide
Questions
Is anything installed inside the VMs?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported