WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Multiple VMs - one static routable IP address

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] Multiple VMs - one static routable IP address
From: Nico Kadel-Garcia <nkadel@xxxxxxxxx>
Date: Fri, 18 May 2007 10:55:10 +0100
Delivery-date: Fri, 18 May 2007 02:51:10 -0700
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:content-type:content-transfer-encoding; b=KeKBfhZCjScyrkJRMi9vaul4Y/hJ8aS6d7F+tzUlBWz4mFXwvTbj181lzcXbNyY5+BzAtHxw0DGBt3vnlGQV+Nj65f7CqmbWPFHmqQahCPm4fXVjKW2A81mdGW5BSB6xBuu+FI1RYWpzUD+SsJkoRXUceL/xGQZLlE2m3VVZoBw=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:content-type:content-transfer-encoding; b=K8tTgUt+K2S7nNJPz0k88K//+Jbm91uBwPv1hkcVwNMn8WRuBDx9bhPyLOK3gUbQTzAuZkvbhI9lmsQkcqLcU0NiK3TOLkPr9h5SjykpuYrL+WEkEvTxjurD+w0DSjOMB2IVSiraclAIz+lHN/HWlBL8oCIMuMI+VBcrnAF5638=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <20070518082148.GH32664@xxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <Pine.LNX.4.64.0705160855430.16847@xxxxxxxxxxxxxxxxxxxxxxxxxxxx> <20070517043259.GA20769@xxxxxxxxxxxx> <Pine.LNX.4.64.0705172212020.31964@xxxxxxxxxxxxxxxxxxxxxxxxxxxx> <20070518082148.GH32664@xxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Thunderbird 1.5.0.10 (Windows/20070221)
Alex Samad wrote:
On Thu, May 17, 2007 at 10:24:24PM -0500, cyber@xxxxxxxxx wrote:

Originally I was planning on putting all my own personal websites and email on Domain-0, as well as an iptables based firewall. Having read more, seems like the recommendation is to keep Domain-0 behind a DomU where the firewall runs. Makes sense, and doesn't seem difficult to do... just a new paradigm for me. I've always only had one server, and it did everything and anything. I love the idea of breaking it all up from a security and manageability standpoint... just not sure what to do about getting all the bits to the right VMs that need to be routed correctly.

if its for security of apps, why not look at chroot ?

chroot for OpenSSH has never been well-supported. (I used to be the maintainer of that add-on functionality, and it remains rejected by the core authors to this day, much to my lament.) WebDAV over HTTPS works well for upload/download sites, and avoids the shell access and local account problems of SSH.

I'm not a believer in external, hardware firewalls, to avoid the complexities and difficulties of maintaining my own software ones.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users