Become a Beta Tester

Xen · Platform

Frabs for Xen

On a Xen host, Frabs lists the running domains and watches each VM's virtual interface.

Xen

Protects
Xen virtual machines
Recognised by
The xen-utils or xen-hypervisor packages
Watches
vif<domid>.<n>
Panel links
Not needed

How it works

How Frabs works on Xen

  1. 01

    Install

    One command as root on the server. It reads the setup without changing anything.

  2. 02

    Recognise Xen

    The xen-utils or xen-hypervisor packages tells the sensor which platform it is on.

  3. 03

    Find every guest

    xl list for each running domain.

  4. 04

    You confirm

    You review what it will watch. Protection starts within 30 seconds of confirming.

Networking

What it watches, and what it leaves alone

vif<domid>.<n>

One per VM network device

Bridges. The bridges your VMs attach to, such as xenbr0.

How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.

An example plan

PlatformXen
Watchesvif12.0, …
Leaves aloneBridges with no guests
Changes madeNone until you act

Get started

Install on Xen

On the server, as root

curl -fsSL https://install.frabs.net | sh -s -- --token frb_...

Questions

Is anything installed inside the VMs?
No. The sensor runs on the server itself, never inside a customer's guest.
Does Frabs change my bridges or firewall?
No. It counts traffic in its own nftables table on each guest interface, and only acts when your rules or your team say so.
What happens if I add a bridge or move guests?
The server's page shows that the layout changed. Run frabs reconnect, review the updated plan and confirm.
What if the sensor stops?
Its network changes are removed and traffic carries on, unless you chose fail-closed.