🚀 Getting Started
Installing Virtlix on a Fresh Server
Server Requirements & Partition Layout
Activating Your License
Your First VPS
🖥️ VPS Management
Creating and Configuring a VPS
Cloning and Rebuilding a VPS
Creating a Reusable Template from a VPS
Resource Plans and Per-VM Limits
Windows Guest Support
Rescue Mode: Recovering a Broken VPS
📦 LXC Containers
LXC Containers: What They Are and When to Use Them
Creating and Managing an LXC Container
LXC Container Limitations vs KVM
🌐 Networking & Firewall
IP Pool and Network Modes
VPS Firewall Rules
Server-Level Firewall Plans
Console Access: noVNC and the Web Terminal
Network Filtering: Anti-Spoofing and Rogue RA Protection
IPv6 Dual-Stack Networking
Power DNS Integration and Reverse DNS Zones
Adding Multiple IPs and Per-IP MAC Overrides
💽 Storage & Hardware
Storage Pools: Local Disk and Remote NFS
PCI and USB Device Passthrough
Attaching Extra Volumes to a VPS
💾 Backups & OS Templates
Automated Backups and Backup Destinations
Managing OS Templates
Uploading and Using ISOs
Media Groups
🔑 Multi-Server & Licensing
Understanding Your License and VPS Limits
Master Configuration and Security Settings
Registering and Controlling Remote Servers
Webhook Callbacks
Selling VPS Hosting Through WHMCS
🔐 Account & Security
Two-Factor Authentication
Docs /
Networking & Firewall /
Network Filtering: Anti-Spoofing and Rogue RA Protection
Network Filtering: Anti-Spoofing and Rogue RA Protection
Network Filtering protects VM traffic against MAC/IP spoofing and rogue IPv6 router advertisements - without it, a compromised or misconfigured guest on a shared bridge could impersonate another VPS's address, or advertise itself as an IPv6 router and hijack traffic from other guests on the same network.
Three filter options are available, chosen per-VM or as an install-wide default in Master Settings:
- Libvirt (built-in) - libvirt's own standard
clean-trafficfilter. Solid baseline protection with no extra configuration. - Native Performance - a lighter-weight profile covering IPv4 and IPv6 MAC/IP spoofing plus rogue router-advertisement/DHCPv6 guard, implemented directly as host-level
ebtables/iptables/ip6tablesrules rather than libvirt's own filter chain. - Custom (JSON) - write your own filter rule set if neither built-in option fits your exact network policy.
Set a default under Master Settings so every new VPS gets sensible protection automatically, and override it per-VM from that VPS's Network tab for any guest that needs a different policy (or none at all).