WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Ideal(istic) Xen firewall design

To: "Dirk H. Schulz" <dirk.schulz@xxxxxxxxxxxxx>
Subject: Re: [Xen-users] Ideal(istic) Xen firewall design
From: Marcus Brown <marcusbrutus@xxxxxxxxxxxxxxxx>
Date: Mon, 15 Aug 2005 16:35:20 +1000
Cc: Mike Tierney <miket@xxxxxxxxxxxxxxxx>, xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Mon, 15 Aug 2005 06:39:45 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <43002F9D.7000802@xxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <200508142130.j7ELUZ7k011456@xxxxxxxxxxxxxxxx> <43002F9D.7000802@xxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Debian Thunderbird 1.0.2 (X11/20050602)
Hi Dirk and Mike,

Dirk H. Schulz wrote:
> Hi Mike,
> 
> Mike Tierney schrieb:
> 
>> But it is still tempting to just do away with the seperate firewall vm
>> and
>> do all the firewalling in Dom0!
>>  
>>

Having got my Firewall domain working reasonably well I'd have to say that
I wouldn't go back! :) Extremely handy being able to create a Firewall,
restart it, swap in another version ... all without having to restart
my other domains!



> There is one more reason to put the firewall into a guest system: The
> guests use the smaller kernels (without hardware support etc.), so there
> is less possibility of kernel bugs that can be used to crack the
> firewall. It is more of a statistic perspective but with firewalling
> everything should be used to avoid leaks, I think.
> 

The firewall domain _does_ have hardware support (ie. network cards),
so I'm not sure if your logic applies.
(ie. Firewall still has DMA)
But, still, everything else is/can be virtualised, so it's still a step
up from a dom0 (IMHO).

Marcus.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users