|   | 
      | 
  
  
      | 
      | 
  
 
     | 
    | 
  
  
     | 
    | 
  
  
    |   | 
      | 
  
  
    | 
         
xen-users
Re: [Xen-users] Ideal(istic) Xen firewall design
 
Hi Mike,
Mike Tierney schrieb:
 
But it is still tempting to just do away with the seperate firewall vm and
do all the firewalling in Dom0!
  
 There is one more reason to put the firewall into a guest system: The 
guests use the smaller kernels (without hardware support etc.), so there 
is less possibility of kernel bugs that can be used to crack the 
firewall. It is more of a statistic perspective but with firewalling 
everything should be used to avoid leaks, I think.
 I begin to like the idea of moving my firewall into a guest system. I 
will start first work on that today.
Dirk
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
 
 |   
 
| <Prev in Thread] | 
Current Thread | 
[Next in Thread>
 |  
- Re: [Xen-users] Ideal(istic) Xen firewall design, (continued)
- Re: [Xen-users] Ideal(istic) Xen firewall design, Andreas Seuss
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
- Message not available
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
 
- RE: [Xen-users] Ideal(istic) Xen firewall design, Mike Tierney
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
 
- Re: [Xen-users] Ideal(istic) Xen firewall design,
Dirk H. Schulz <=
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 
- Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
 
  
  
  
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 
- Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Mark Williamson
 
- Re: [Xen-users] Ideal(istic) Xen firewall design, Nicholas Lee
 - Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
 
 
 |  
  
 | 
    | 
  
  
    |   | 
    |