# Routing in OpenNebula VMs

**URL:** https://forum.opennebula.io/t/routing-in-opennebula-vms/4160
**Category:** Product Support
**Created:** [April 18, 2017, 10:28am UTC](https://forum.opennebula.io/t/routing-in-opennebula-vms/4160 "2017-04-18T10:28:27Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Christoph](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@Christoph](https://forum.opennebula.io/u/Christoph)
#### Post date: [April 18, 2017, 10:28am UTC](https://forum.opennebula.io/t/routing-in-opennebula-vms/4160/1 "2017-04-18T10:28:27Z")

</div>

Hello,

if I want to prevent all VMs from being able to route between different virtual networks, it is sufficient to not allow creation of what is explicitly called “Virtual Router”, or do I have to restrict users to a single virtual network? That is, is routing possible inside a virtual machine though it is not defined as a virtual router?

Regards  
Christoph

---

<div class="post-metadata">

### Author: ![feldsam](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/feldsam/32/4441_2.png) [@feldsam](https://forum.opennebula.io/u/feldsam)
#### Post date: [April 19, 2017, 10:24am UTC](https://forum.opennebula.io/t/routing-in-opennebula-vms/4160/2 "2017-04-19T10:24:45Z")

</div>

Hello, yes of course, routing is possible in any VM - it is just as any other linux/windows server, which have capabilities to route. Good practise is enable IP and MAC spoofing and also set bandwidth limits to networks, so user can change IP/MAC address and cant consume whole for ex. 1Gbps network.

I don’t see any problem with user can route between netowrks. Why you want restrict it?

---

<div class="post-metadata">

### Author: ![Christoph](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@Christoph](https://forum.opennebula.io/u/Christoph)
#### Post date: [April 19, 2017, 11:12am UTC](https://forum.opennebula.io/t/routing-in-opennebula-vms/4160/3 "2017-04-19T11:12:09Z")

</div>

I want to restrict it because I want to define VLAN virtual networks that already exist as real networks for real machines and routing inside a VM would bypass access control lists on our real routers.

---

<div class="post-metadata">

### Author: ![feldsam](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/feldsam/32/4441_2.png) [@feldsam](https://forum.opennebula.io/u/feldsam)
#### Post date: [April 19, 2017, 12:12pm UTC](https://forum.opennebula.io/t/routing-in-opennebula-vms/4160/4 "2017-04-19T12:12:31Z")

</div>

so you can attach only one network to VMs which are not under your control
