|
|
|
|
|
|
|
|
|
|
xen-users
Re: [Xen-users] Ideal(istic) Xen firewall design
Hi Markus,
Marcus Brown schrieb:
Hi Dirk,
Dirk H. Schulz wrote:
Hi Marcus,
thanks for so much info!
Just a short question before I start digging into your configs: What do
you gain by running the firewall inside a privileged guest system
instead of inside dom0?
It's modular, restartable, replaceable, ...
(ie. I can reboot the firewall without rebooting all the domUs)
That is a very good reason. I did not think of that, I have to admit.
errr
oh, and someone gaining root access to the firewall won't be able to
play with xend, or the filesystems of the domUs.
Oh, err, shouldn't it be more difficult to get root access to the
firewall than to the other systems? That's one thing firewalls are for,
aren't they? :-)
I'm sure there are other good reasons :)
Yes, there are. This way one could have two firewalls to hide the domU
network behind and a vpn server inbetween just for training (setting up
vpn with dynamic routing, e.g.). Lots to play with on rainy weekends. :-)
One could even setup complex OSPF scenarios just for testing. I start
loving this concept ...
Dirk
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
|
<Prev in Thread] |
Current Thread |
[Next in Thread>
|
- [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Andreas Seuss
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Message not available
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design,
Dirk H. Schulz <=
- RE: [Xen-users] Ideal(istic) Xen firewall design, Mike Tierney
- Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
- Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Re: [Xen-users] Ideal(istic) Xen firewall design, Mark Williamson
- Re: [Xen-users] Ideal(istic) Xen firewall design, Nicholas Lee
|
|
|
|
|