WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Securing the host's networking ?

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] Securing the host's networking ?
From: Dominique Rousseau <d.rousseau@xxxxxxx>
Date: Tue, 17 May 2005 09:11:59 +0200
Delivery-date: Tue, 17 May 2005 07:11:34 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <8fe610c205051607172c122428@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <8fe610c205051607172c122428@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.5.9i
Le Mon, May 16, 2005 at 10:17:34AM -0400, Dana Lux [dana.lux@xxxxxxxxx] a écrit:
> Internet <---> eth0 <---> xen-br0 <----> Xen guests
> 
> I do have two questions:
> 
> First, I've noticed that on most bridging HOWTO's they state that eth0
> should be set to 0.0.0.0, however I've noticed that on my machine it
> is configured with an IP (via the distribution init scripts) and that
> xen-br0 simply copies its IP.  Is this normal ?

Yes, that's how it is supposed to be (in a simple case like yours).
The matter is that an interface that once an interface is part of a
bridge it doesn't see traffic on ethX anymore but on brX, so in cases
described in the HOWTOs they just consider that ethX should as well have
0.0.0.0
But in the case of the xen scripts, they just copy the IP of ethX to brX
so as not to cut the network link.



Dom

-- 
Dominique Rousseau 
Neuronnexion, Prestataire Internet & Intranet
57, route de Paris 80000 Amiens
tel: 03 22 71 61 90 - fax: 03 22 71 61 99 - http://www.neuronnexion.fr

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>