WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] dom0 networking

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] dom0 networking
From: Jonathan Vogt <xen-users@xxxxxxxxxxx>
Date: Fri, 7 Jul 2006 09:21:27 +0200
Delivery-date: Fri, 07 Jul 2006 00:22:52 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <44ADDCED.6010509@xxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <44ADDCED.6010509@xxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.3
Hi Paolo
Am Freitag 07 Juli 2006 06:02 schrieb Paolo Supino:
> Hi
>
>   I have a bit of a problem that I have to overcome. I have 2 networks
> that I need to run different system on (DMZ and internal). I have one
> computer that has two NICs and I thought of doing the following: Setup
> Xen and run dom0 without giving it an IP address. Setup one domU that is
> bridged through the first NIC and a second domU that is bridge through a
> second bridge on the second interface. 
Should be possible. You could even hide the nics from dom0 and hand them over 
to the domU. Thats my current setup.
> The result of this setup is that 
> I have 2 domUs that are totally separated even on the network level and
> dom0 that is unreachable because it doesn't exist in layer 3 and above.
> The questions I have:
> 1. Is it possible not to give dom0 an IP address at all and still have
> the domU be able to network?
Yup. Since in standard setup the physical device and the device dom0 sees as 
eth0 are different. The physical device becomes peth0 and is attached to a 
bridge and veth0 is renamed to eth0 and then gets the ip and mac of the old 
eth0.
you just might want to modify /etc/xen/scripts/network-bridge. There might be 
an easier way which I'm missing right now, since I myself just started
> 2. Is such a setup has a security weakness that I'm not seeing?
Don't know about that one...

Jonathan

Attachment: pgpw0E7IL70Sn.pgp
Description: PGP signature

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>