Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

July 4TH Sale (NEW CPU'S)

2»

Comments

  • Location is AMS, would've liked geolocation to show that (helps with what I will host on the machine), machine is very snappy!

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-05-11                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Fri Jun 26 14:47:42 UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 47 minutes
    Processor  : QEMU Virtual CPU version 2.5+
    CPU cores  : 8 @ 4291.936 MHz
    AES-NI     : ✔ Enabled
    VM-x/AMD-V : ❌ Disabled
    RAM        : 15.6 GiB
    Swap       : 0.0 KiB
    Disk       : 295.2 GiB
    Distro     : Debian GNU/Linux 13 (trixie)
    Kernel     : 6.12.94+deb13-cloud-amd64
    VM Type    : KVM
    IPv4/IPv6  : ✔ Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Ipxo LLC
    ASN        : AS402349 Gatewaysentry LLC
    Host       : Ipxo LLC
    Location   : Wilmington, Delaware (DE)
    Country    : United States
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/sda1):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 246.22 MB/s  (61.5k) | 501.47 MB/s   (7.8k)
    Write      | 246.87 MB/s  (61.7k) | 504.11 MB/s   (7.8k)
    Total      | 493.09 MB/s (123.2k) | 1.00 GB/s    (15.7k)
               |                      |                     
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 746.93 MB/s   (1.4k) | 714.38 MB/s    (697)
    Write      | 786.62 MB/s   (1.5k) | 761.96 MB/s    (744)
    Total      | 1.53 GB/s     (2.9k) | 1.47 GB/s     (1.4k)
    
    Geekbench 6 Benchmark Test:
    ---------------------------------
    Test            | Value                         
                    |                               
    Single Core     |      2750                         
    Multi Core      |       12247                        
    Full Test       | https://browser.geekbench.com/v6/cpu/18491915
    
    YABS completed in 5 min 12 sec
    
    Thanked by 2buggedout tof
  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @alincupunct said:
    Location is AMS, would've liked geolocation to show that (helps with what I will host on the machine), machine is very snappy!

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-05-11                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Fri Jun 26 14:47:42 UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 47 minutes
    Processor  : QEMU Virtual CPU version 2.5+
    CPU cores  : 8 @ 4291.936 MHz
    AES-NI     : ✔ Enabled
    VM-x/AMD-V : ❌ Disabled
    RAM        : 15.6 GiB
    Swap       : 0.0 KiB
    Disk       : 295.2 GiB
    Distro     : Debian GNU/Linux 13 (trixie)
    Kernel     : 6.12.94+deb13-cloud-amd64
    VM Type    : KVM
    IPv4/IPv6  : ✔ Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Ipxo LLC
    ASN        : AS402349 Gatewaysentry LLC
    Host       : Ipxo LLC
    Location   : Wilmington, Delaware (DE)
    Country    : United States
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/sda1):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 246.22 MB/s  (61.5k) | 501.47 MB/s   (7.8k)
    Write      | 246.87 MB/s  (61.7k) | 504.11 MB/s   (7.8k)
    Total      | 493.09 MB/s (123.2k) | 1.00 GB/s    (15.7k)
               |                      |                     
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 746.93 MB/s   (1.4k) | 714.38 MB/s    (697)
    Write      | 786.62 MB/s   (1.5k) | 761.96 MB/s    (744)
    Total      | 1.53 GB/s     (2.9k) | 1.47 GB/s     (1.4k)
    
    Geekbench 6 Benchmark Test:
    ---------------------------------
    Test            | Value                         
                    |                               
    Single Core     |      2750                         
    Multi Core      |       12247                        
    Full Test       | https://browser.geekbench.com/v6/cpu/18491915
    
    YABS completed in 5 min 12 sec
    

    We hope you enjoy the server! <3

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    Thank you for all the users who signed up,

    We are almost out of stock in Amsterdam, Please bare with us as we might have to disable orders in Amsterdam to restock.

  • How quickly does a VPS activate?

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @SokolAlex said:
    How quickly does a VPS activate?

    Our automated installer is currently down, I would say within the next 6-8 hours.

  • gbzret4dgbzret4d Member

    Imho the included traffic is too low

  • cwatercwater Member

    it`s cn2 or 4837?
    I test it best working from China.

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @cwater said:
    it`s cn2 or 4837?
    I test it best working from China.

    4837 Premium

  • cwatercwater Member

    @gatewaysentryllc said:

    @cwater said:
    it`s cn2 or 4837?
    I test it best working from China.

    4837 Premium

    I cant register on your website. Whether I have VPN on or off, it consistently identifies me as a bot

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @cwater said:

    @gatewaysentryllc said:

    @cwater said:
    it`s cn2 or 4837?
    I test it best working from China.

    4837 Premium

    I cant register on your website. Whether I have VPN on or off, it consistently identifies me as a bot

    I would recommend disabling any extensions that block javascript.

  • o7o2p7o7o2p7 Member

    I missed it—when is the next sale?

  • tzulitzuli Member

    @o7o2p7 said:
    I missed it—when is the next sale?

    On the Chinese version of LET they have a deal that lasts through the end of July

    Thanked by 1o7o2p7
  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @tzuli said:

    @o7o2p7 said:
    I missed it—when is the next sale?

    On the Chinese version of LET they have a deal that lasts through the end of July

    Tis would be correcto.

  • cccsscccss Member

    It looks like good value for money.

  • forestforest Member

    @alincupunct said: Processor : QEMU Virtual CPU version 2.5+

    Do you think you (or someone else with this plan) could paste the output of lscpu?

  • tzulitzuli Member

    @forest said:

    @alincupunct said: Processor : QEMU Virtual CPU version 2.5+

    Do you think you (or someone else with this plan) could paste the output of lscpu?

    I don't have a plan with them yet (I'm also considering), but I found this (for LAX VPS) if it helps:
    ✘ VT-x/AMD-V
    ✔ AES-NI
    ✔ AVX2
    ✔ BMI1
    ✔ BMI2
    ✘ EPT/NPT

    Also:

    Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    Thanked by 1forest
  • forestforest Member
    edited July 18

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    More info: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    Thanked by 1tzuli
  • tzulitzuli Member

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

  • forestforest Member
    edited July 18

    @tzuli said:

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

    I don't have an account with them.

    @gatewaysentryllc If you'd like, I can explain in more detail what the limitations of CPU passthrough are and how it actually improves security for the guest itself, neighboring guests, and the host. I can also give some QEMU hardening advice for disabling features that do have a negative security impact but which most people don't recognize.

  • @gatewaysentryllc said:

    @alincupunct said:
    Location is AMS, would've liked geolocation to show that (helps with what I will host on the machine), machine is very snappy!

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-05-11                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Fri Jun 26 14:47:42 UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 47 minutes
    Processor  : QEMU Virtual CPU version 2.5+
    CPU cores  : 8 @ 4291.936 MHz
    AES-NI     : ✔ Enabled
    VM-x/AMD-V : ❌ Disabled
    RAM        : 15.6 GiB
    Swap       : 0.0 KiB
    Disk       : 295.2 GiB
    Distro     : Debian GNU/Linux 13 (trixie)
    Kernel     : 6.12.94+deb13-cloud-amd64
    VM Type    : KVM
    IPv4/IPv6  : ✔ Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Ipxo LLC
    ASN        : AS402349 Gatewaysentry LLC
    Host       : Ipxo LLC
    Location   : Wilmington, Delaware (DE)
    Country    : United States
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/sda1):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 246.22 MB/s  (61.5k) | 501.47 MB/s   (7.8k)
    Write      | 246.87 MB/s  (61.7k) | 504.11 MB/s   (7.8k)
    Total      | 493.09 MB/s (123.2k) | 1.00 GB/s    (15.7k)
               |                      |                     
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 746.93 MB/s   (1.4k) | 714.38 MB/s    (697)
    Write      | 786.62 MB/s   (1.5k) | 761.96 MB/s    (744)
    Total      | 1.53 GB/s     (2.9k) | 1.47 GB/s     (1.4k)
    
    Geekbench 6 Benchmark Test:
    ---------------------------------
    Test            | Value                         
                    |                               
    Single Core     |      2750                         
    Multi Core      |       12247                        
    Full Test       | https://browser.geekbench.com/v6/cpu/18491915
    
    YABS completed in 5 min 12 sec
    

    We hope you enjoy the server! <3

    Please may we have a non homo captcha n sign-up, this one wont even allow me to complete on my actual ISP internet.

  • @forest said:

    @alincupunct said: Processor : QEMU Virtual CPU version 2.5+

    Do you think you (or someone else with this plan) could paste the output of lscpu?

    Yes.

    lscpu
    Architecture:                x86_64
      CPU op-mode(s):            32-bit, 64-bit
      Address sizes:             40 bits physical, 48 bits virtual
      Byte Order:                Little Endian
    CPU(s):                      8
      On-line CPU(s) list:       0-7
    Vendor ID:                   AuthenticAMD
      Model name:                QEMU Virtual CPU version 2.5+
        CPU family:              15
        Model:                   107
        Thread(s) per core:      1
        Core(s) per socket:      8
        Socket(s):               1
        Stepping:                1
        BogoMIPS:                8583.87
        Flags:                   fpu de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse 
                                 sse2 ht syscall nx lm rep_good nopl xtopology cpuid extd_apicid tsc_known_freq pni ssse3 
                                 fma cx16 sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c hypervisor lahf_lm cmp_lega
                                 cy abm 3dnowprefetch vmmcall bmi1 avx2 bmi2 avx512f avx512dq avx512cd avx512bw avx512vl
    Virtualization features:     
      Hypervisor vendor:         KVM
      Virtualization type:       full
    Caches (sum of all):         
      L1d:                       512 KiB (8 instances)
      L1i:                       512 KiB (8 instances)
      L2:                        4 MiB (8 instances)
      L3:                        128 MiB (8 instances)
    NUMA:                        
      NUMA node(s):              1
      NUMA node0 CPU(s):         0-7
    Vulnerabilities:             
      Gather data sampling:      Not affected
      Ghostwrite:                Not affected
      Indirect target selection: Not affected
      Itlb multihit:             Not affected
      L1tf:                      Not affected
      Mds:                       Not affected
      Meltdown:                  Not affected
      Mmio stale data:           Not affected
      Old microcode:             Not affected
      Reg file data sampling:    Not affected
      Retbleed:                  Not affected
      Spec rstack overflow:      Not affected
      Spec store bypass:         Not affected
      Spectre v1:                Mitigation; usercopy/swapgs barriers and __user pointer sanitization
      Spectre v2:                Mitigation; Retpolines; STIBP disabled; RSB filling; PBRSB-eIBRS Not affected; BHI Not af
                                 fected
      Srbds:                     Not affected
      Tsa:                       Not affected
      Tsx async abort:           Not affected
      Vmscape:                   Not affected
    
    Thanked by 2tzuli forest
  • forestforest Member
    edited July 18

    @alincupunct said: Flags: fpu de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ht syscall nx lm rep_good nopl xtopology cpuid extd_apicid tsc_known_freq pni ssse3 fma cx16 sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c hypervisor lahf_lm cmp_legacy abm 3dnowprefetch vmmcall bmi1 avx2 bmi2 avx512f avx512dq avx512cd avx512bw avx512vl

    Ouch, yeah a lot of important features used for security are missing like smep, smap, umip, pcid, invpcid, rdrand, rdseed, ibrs, ibpb, stibp, pclmulqdq, sha_ni, pku, ospke, gfni... Some of which, when missing, allow guests to attack each other.

  • @forest said:

    @alincupunct said: Flags: fpu de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ht syscall nx lm rep_good nopl xtopology cpuid extd_apicid tsc_known_freq pni ssse3 fma cx16 sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c hypervisor lahf_lm cmp_legacy abm 3dnowprefetch vmmcall bmi1 avx2 bmi2 avx512f avx512dq avx512cd avx512bw avx512vl


    Ouch, yeah a lot of important features used for security are missing like smep, smap, umip, pcid, invpcid, rdrand, rdseed, ibrs, ibpb, stibp, pclmulqdq, sha_ni, pku, ospke, gfni... Some of which, when missing, allow guests to attack each other.

    I won't be renewing it either way, had some other issues regarding my usecase (they were resolved)

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider

    @forest said:

    @tzuli said:

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

    I don't have an account with them.

    @gatewaysentryllc If you'd like, I can explain in more detail what the limitations of CPU passthrough are and how it actually improves security for the guest itself, neighboring guests, and the host. I can also give some QEMU hardening advice for disabling features that do have a negative security impact but which most people don't recognize.

    The setup of "QEMU CPU" isn't based off just a simple reason of security, one of the most major points of this is having the ability to migrate servers from location to location without instruction compatibility issues , by us exposing a common-denominator CPU model, every host in the cluster looks identical to the guest, so VMs can move freely between machines of different generations as we use different CPU's per location.

    9950x, 9960x, 9970x, 9980x, 9275F and our latest being added to the cluster the 4565P.

    The design of our network is for users to be able to send services (migration between datacenters that have different CPU's) and have the highest availability even during hardware failure, being able to pull from our replication service within 10 minutes> depending on disk size and amount of users required to migrate.

  • forestforest Member
    edited July 18

    @gatewaysentryllc said:

    @forest said:

    @tzuli said:

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

    I don't have an account with them.

    @gatewaysentryllc If you'd like, I can explain in more detail what the limitations of CPU passthrough are and how it actually improves security for the guest itself, neighboring guests, and the host. I can also give some QEMU hardening advice for disabling features that do have a negative security impact but which most people don't recognize.

    The setup of "QEMU CPU" isn't based off just a simple reason of security, one of the most major points of this is having the ability to migrate servers from location to location without instruction compatibility issues , by us exposing a common-denominator CPU model, every host in the cluster looks identical to the guest, so VMs can move freely between machines of different generations as we use different CPU's per location.

    9950x, 9960x, 9970x, 9980x, 9275F and our latest being added to the cluster the 4565P.

    The design of our network is for users to be able to send services (migration between datacenters that have different CPU's) and have the highest availability even during hardware failure, being able to pull from our replication service within 10 minutes> depending on disk size and amount of users required to migrate.

    Yep that is a use, but you have it configured not to the least common denominator, but to qemu64. Surely every single device you own has SMEP, for example, but it's not exposed which severely reduces guest security. Instead you should set it to whatever your base, lowest model is, which surely has RDRAND, SMEP, PCID, etc. I assume you don't have any pre-Sandy Bridge CPUs, right?

  • gatewaysentryllcgatewaysentryllc Member, Patron Provider
    edited July 18

    @forest said:

    @gatewaysentryllc said:

    @forest said:

    @tzuli said:

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

    I don't have an account with them.

    @gatewaysentryllc If you'd like, I can explain in more detail what the limitations of CPU passthrough are and how it actually improves security for the guest itself, neighboring guests, and the host. I can also give some QEMU hardening advice for disabling features that do have a negative security impact but which most people don't recognize.

    The setup of "QEMU CPU" isn't based off just a simple reason of security, one of the most major points of this is having the ability to migrate servers from location to location without instruction compatibility issues , by us exposing a common-denominator CPU model, every host in the cluster looks identical to the guest, so VMs can move freely between machines of different generations as we use different CPU's per location.

    9950x, 9960x, 9970x, 9980x, 9275F and our latest being added to the cluster the 4565P.

    The design of our network is for users to be able to send services (migration between datacenters that have different CPU's) and have the highest availability even during hardware failure, being able to pull from our replication service within 10 minutes> depending on disk size and amount of users required to migrate.

    Yep that is a use, but you have it configured not to the least common denominator, but to qemu64. Surely every single device you own has SMEP, for example, but it's not exposed which severely reduces guest security. Instead you should set it to whatever your base, lowest model is, which surely has RDRAND, SMEP, PCID, etc. I assume you don't have any pre-Sandy Bridge CPUs, right?

    Haha yes we do not have anything pre sandy bridge,

    I will forward this to our OPs team and see what they say.

  • forestforest Member

    @gatewaysentryllc said:

    @forest said:

    @gatewaysentryllc said:

    @forest said:

    @tzuli said:

    @forest said:

    @tzuli said: Sadly we can't allow CPU passthrough due to possible vulnerabilities.

    That's factually incorrect (and I say that as someone whose day job is infosec). In fact, passthrough improves security (SMEP, SMAP, UMIP, etc.). Passthrough, with few exceptions, doesn't actually disable features, it just stops advertising them. The guest can just override most of what the host tries to "disable". This is because most instructions do not support trapping to trigger a #vmexit, only a few critical ones. Disable the CLFLUSH feature in the HV, for example, and nothing happens except it's no longer advertised, but you can still use it for things like FLUSH+RELOAD side-channel attacks.

    Unless they mean disabling nested virtualization (EPT and friends), which you can do without disabling passthrough...

    I wrote a bit about that here: https://lowendtalk.com/discussion/218882/re-enabling-aes-ni-on-vpses-that-dont-pass-the-feature-through/p1

    It was about CPU passthrough

    That quote was from their forum rep. That person's been pretty candid about not being a tech expert. If you were to open a ticket you may get a different response

    I don't have an account with them.

    @gatewaysentryllc If you'd like, I can explain in more detail what the limitations of CPU passthrough are and how it actually improves security for the guest itself, neighboring guests, and the host. I can also give some QEMU hardening advice for disabling features that do have a negative security impact but which most people don't recognize.

    The setup of "QEMU CPU" isn't based off just a simple reason of security, one of the most major points of this is having the ability to migrate servers from location to location without instruction compatibility issues , by us exposing a common-denominator CPU model, every host in the cluster looks identical to the guest, so VMs can move freely between machines of different generations as we use different CPU's per location.

    9950x, 9960x, 9970x, 9980x, 9275F and our latest being added to the cluster the 4565P.

    The design of our network is for users to be able to send services (migration between datacenters that have different CPU's) and have the highest availability even during hardware failure, being able to pull from our replication service within 10 minutes> depending on disk size and amount of users required to migrate.

    Yep that is a use, but you have it configured not to the least common denominator, but to qemu64. Surely every single device you own has SMEP, for example, but it's not exposed which severely reduces guest security. Instead you should set it to whatever your base, lowest model is, which surely has RDRAND, SMEP, PCID, etc. I assume you don't have any pre-Sandy Bridge CPUs, right?

    Haha yes we do not have anything pre sandy bridge,

    I will forward this to our OPs team and see what they say.

    These are the available models:

      486                   (alias configured by machine type)
      486-v1
      Broadwell             (alias configured by machine type)
      Broadwell-IBRS        (alias of Broadwell-v3)
      Broadwell-noTSX       (alias of Broadwell-v2)
      Broadwell-noTSX-IBRS  (alias of Broadwell-v4)
      Broadwell-v1          Intel Core Processor (Broadwell)
      Broadwell-v2          Intel Core Processor (Broadwell, no TSX)
      Broadwell-v3          Intel Core Processor (Broadwell, IBRS)
      Broadwell-v4          Intel Core Processor (Broadwell, no TSX, IBRS)
      Cascadelake-Server    (alias configured by machine type)
      Cascadelake-Server-noTSX  (alias of Cascadelake-Server-v3)
      Cascadelake-Server-v1  Intel Xeon Processor (Cascadelake)
      Cascadelake-Server-v2  Intel Xeon Processor (Cascadelake) [ARCH_CAPABILITIES]
      Cascadelake-Server-v3  Intel Xeon Processor (Cascadelake) [ARCH_CAPABILITIES, no TSX]
      Cascadelake-Server-v4  Intel Xeon Processor (Cascadelake) [ARCH_CAPABILITIES, EPT switching, no TSX]
      Cascadelake-Server-v5  Intel Xeon Processor (Cascadelake) [ARCH_CAPABILITIES, EPT switching, XSAVES, no TSX]
      ClearwaterForest      (alias configured by machine type)
      ClearwaterForest-v1   Intel Xeon Processor (ClearwaterForest)
      Conroe                (alias configured by machine type)
      Conroe-v1             Intel Celeron_4x0 (Conroe/Merom Class Core 2)
      Cooperlake            (alias configured by machine type)
      Cooperlake-v1         Intel Xeon Processor (Cooperlake)
      Cooperlake-v2         Intel Xeon Processor (Cooperlake) [XSAVES]
      Denverton             (alias configured by machine type)
      Denverton-v1          Intel Atom Processor (Denverton)
      Denverton-v2          Intel Atom Processor (Denverton) [no MPX, no MONITOR]
      Denverton-v3          Intel Atom Processor (Denverton) [XSAVES, no MPX, no MONITOR]
      Dhyana                (alias configured by machine type)
      Dhyana-v1             Hygon Dhyana Processor
      Dhyana-v2             Hygon Dhyana Processor [XSAVES]
      EPYC                  (alias configured by machine type)
      EPYC-Genoa            (alias configured by machine type)
      EPYC-Genoa-v1         AMD EPYC-Genoa Processor
      EPYC-IBPB             (alias of EPYC-v2)
      EPYC-Milan            (alias configured by machine type)
      EPYC-Milan-v1         AMD EPYC-Milan Processor
      EPYC-Milan-v2         AMD EPYC-Milan-v2 Processor
      EPYC-Rome             (alias configured by machine type)
      EPYC-Rome-v1          AMD EPYC-Rome Processor
      EPYC-Rome-v2          AMD EPYC-Rome Processor
      EPYC-Rome-v3          AMD EPYC-Rome-v3 Processor
      EPYC-Rome-v4          AMD EPYC-Rome-v4 Processor (no XSAVES)
      EPYC-v1               AMD EPYC Processor
      EPYC-v2               AMD EPYC Processor (with IBPB)
      EPYC-v3               AMD EPYC Processor
      EPYC-v4               AMD EPYC-v4 Processor
      GraniteRapids         (alias configured by machine type)
      GraniteRapids-v1      Intel Xeon Processor (GraniteRapids)
      GraniteRapids-v2      Intel Xeon Processor (GraniteRapids)
      Haswell               (alias configured by machine type)
      Haswell-IBRS          (alias of Haswell-v3)
      Haswell-noTSX         (alias of Haswell-v2)
      Haswell-noTSX-IBRS    (alias of Haswell-v4)
      Haswell-v1            Intel Core Processor (Haswell)
      Haswell-v2            Intel Core Processor (Haswell, no TSX)
      Haswell-v3            Intel Core Processor (Haswell, IBRS)
      Haswell-v4            Intel Core Processor (Haswell, no TSX, IBRS)
      Icelake-Server        (alias configured by machine type)
      Icelake-Server-noTSX  (alias of Icelake-Server-v2)
      Icelake-Server-v1     Intel Xeon Processor (Icelake)
      Icelake-Server-v2     Intel Xeon Processor (Icelake) [no TSX]
      Icelake-Server-v3     Intel Xeon Processor (Icelake)
      Icelake-Server-v4     Intel Xeon Processor (Icelake)
      Icelake-Server-v5     Intel Xeon Processor (Icelake) [XSAVES]
      Icelake-Server-v6     Intel Xeon Processor (Icelake) [5-level EPT]
      Icelake-Server-v7     Intel Xeon Processor (Icelake) [TSX, taa-no]
      IvyBridge             (alias configured by machine type)
      IvyBridge-IBRS        (alias of IvyBridge-v2)
      IvyBridge-v1          Intel Xeon E3-12xx v2 (Ivy Bridge)
      IvyBridge-v2          Intel Xeon E3-12xx v2 (Ivy Bridge, IBRS)
      KnightsMill           (alias configured by machine type)
      KnightsMill-v1        Intel Xeon Phi Processor (Knights Mill)
      Nehalem               (alias configured by machine type)
      Nehalem-IBRS          (alias of Nehalem-v2)
      Nehalem-v1            Intel Core i7 9xx (Nehalem Class Core i7)
      Nehalem-v2            Intel Core i7 9xx (Nehalem Core i7, IBRS update)
      Opteron_G1            (alias configured by machine type)
      Opteron_G1-v1         AMD Opteron 240 (Gen 1 Class Opteron)
      Opteron_G2            (alias configured by machine type)
      Opteron_G2-v1         AMD Opteron 22xx (Gen 2 Class Opteron)
      Opteron_G3            (alias configured by machine type)
      Opteron_G3-v1         AMD Opteron 23xx (Gen 3 Class Opteron)
      Opteron_G4            (alias configured by machine type)
      Opteron_G4-v1         AMD Opteron 62xx class CPU
      Opteron_G5            (alias configured by machine type)
      Opteron_G5-v1         AMD Opteron 63xx class CPU
      Penryn                (alias configured by machine type)
      Penryn-v1             Intel Core 2 Duo P9xxx (Penryn Class Core 2)
      SandyBridge           (alias configured by machine type)
      SandyBridge-IBRS      (alias of SandyBridge-v2)
      SandyBridge-v1        Intel Xeon E312xx (Sandy Bridge)
      SandyBridge-v2        Intel Xeon E312xx (Sandy Bridge, IBRS update)
      SapphireRapids        (alias configured by machine type)
      SapphireRapids-v1     Intel Xeon Processor (SapphireRapids)
      SapphireRapids-v2     Intel Xeon Processor (SapphireRapids)
      SapphireRapids-v3     Intel Xeon Processor (SapphireRapids)
      SierraForest          (alias configured by machine type)
      SierraForest-v1       Intel Xeon Processor (SierraForest)
      SierraForest-v2       Intel Xeon Processor (SierraForest)
      Skylake-Client        (alias configured by machine type)
      Skylake-Client-IBRS   (alias of Skylake-Client-v2)
      Skylake-Client-noTSX-IBRS  (alias of Skylake-Client-v3)
      Skylake-Client-v1     Intel Core Processor (Skylake)
      Skylake-Client-v2     Intel Core Processor (Skylake, IBRS)
      Skylake-Client-v3     Intel Core Processor (Skylake, IBRS, no TSX)
      Skylake-Client-v4     Intel Core Processor (Skylake, IBRS, no TSX) [IBRS, XSAVES, no TSX]
      Skylake-Server        (alias configured by machine type)
      Skylake-Server-IBRS   (alias of Skylake-Server-v2)
      Skylake-Server-noTSX-IBRS  (alias of Skylake-Server-v3)
      Skylake-Server-v1     Intel Xeon Processor (Skylake)
      Skylake-Server-v2     Intel Xeon Processor (Skylake, IBRS)
      Skylake-Server-v3     Intel Xeon Processor (Skylake, IBRS, no TSX)
      Skylake-Server-v4     Intel Xeon Processor (Skylake, IBRS, no TSX) [IBRS, EPT switching, no TSX]
      Skylake-Server-v5     Intel Xeon Processor (Skylake, IBRS, no TSX) [IBRS, XSAVES, EPT switching, no TSX]
      Snowridge             (alias configured by machine type)
      Snowridge-v1          Intel Atom Processor (SnowRidge)
      Snowridge-v2          Intel Atom Processor (Snowridge, no MPX)
      Snowridge-v3          Intel Atom Processor (Snowridge, no MPX) [XSAVES, no MPX]
      Snowridge-v4          Intel Atom Processor (Snowridge, no MPX) [no split lock detect, no core-capability]
      Westmere              (alias configured by machine type)
      Westmere-IBRS         (alias of Westmere-v2)
      Westmere-v1           Westmere E56xx/L56xx/X56xx (Nehalem-C)
      Westmere-v2           Westmere E56xx/L56xx/X56xx (IBRS update)
      YongFeng              (alias configured by machine type)
      YongFeng-v1           Zhaoxin YongFeng Processor
      YongFeng-v2           Zhaoxin YongFeng Processor [with the correct model number]
      athlon                (alias configured by machine type)
      athlon-v1             QEMU Virtual CPU version 2.5+
      core2duo              (alias configured by machine type)
      core2duo-v1           Intel(R) Core(TM)2 Duo CPU     T7700  @ 2.40GHz
      coreduo               (alias configured by machine type)
      coreduo-v1            Genuine Intel(R) CPU           T2600  @ 2.16GHz
      kvm32                 (alias configured by machine type)
      kvm32-v1              Common 32-bit KVM processor
      kvm64                 (alias configured by machine type)
      kvm64-v1              Common KVM processor
      n270                  (alias configured by machine type)
      n270-v1               Intel(R) Atom(TM) CPU N270   @ 1.60GHz
      pentium               (alias configured by machine type)
      pentium-v1
      pentium2              (alias configured by machine type)
      pentium2-v1
      pentium3              (alias configured by machine type)
      pentium3-v1
      phenom                (alias configured by machine type)
      phenom-v1             AMD Phenom(tm) 9550 Quad-Core Processor
      qemu32                (alias configured by machine type)
      qemu32-v1             QEMU Virtual CPU version 2.5+
      qemu64                (alias configured by machine type)
      qemu64-v1             QEMU Virtual CPU version 2.5+
      base                  base CPU model type with no features enabled
      host                  processor with all supported host features
      max                   Enables all features supported by the accelerator in the current host
    

    As long as you enable the most recent model in this list compatible with your oldest CPU, it should be fine.

    Thanked by 1gatewaysentryllc
Sign In or Register to comment.