WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] ip conntrack table full

To: jim burns <jim_burn@xxxxxxxxxxxxx>
Subject: Re: [Xen-users] ip conntrack table full
From: "Fajar A. Nugraha" <fajar@xxxxxxxxx>
Date: Mon, 25 Jan 2010 17:24:59 +0700
Cc: xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Mon, 25 Jan 2010 02:25:35 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <201001250508.53327.jim_burn@xxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <201001250508.53327.jim_burn@xxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
On Mon, Jan 25, 2010 at 5:08 PM, jim burns <jim_burn@xxxxxxxxxxxxx> wrote:
> This whole conntrack design strikes me as a serious bug that can lead to DOS
> attacks, even assuming that the counter is 32 bits. And I'm not comfortable
> with dom0 "snooping"/recording traffic on domu, isolation wise. (Yeah, I know,
> anybody can run tcpdump or wireshark on bridged traffic, but this is all being
> recorded. At least it's not world readable.)

That depends on your design.
On my system, dom0 does bridging. It doesn't filter (nor track) domU's
connections. Thus I don't have to worry about DOS in this case.

It's only normal that DOS attacks to domU can bring down the firewall
as well. So if you're worry about this you shouldn't use dom0 as
firewall.

-- 
Fajar

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>