WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] Network issues with SuSE firewall

To: xen-devel@xxxxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-devel] Network issues with SuSE firewall
From: "Gregory Newby" <newby@xxxxxxxx>
Date: Mon, 10 Nov 2003 14:09:31 -0900
Delivery-date: Mon, 10 Nov 2003 23:10:16 +0000
Envelope-to: steven.hand@xxxxxxxxxxxx
In-reply-to: <E1AIOmB-0002CM-00@xxxxxxxxxxxxxxxxxxxx>
List-archive: <http://sourceforge.net/mailarchive/forum.php?forum=xen-devel>
List-help: <mailto:xen-devel-request@lists.sourceforge.net?subject=help>
List-id: List for Xen developers <xen-devel.lists.sourceforge.net>
List-post: <mailto:xen-devel@lists.sourceforge.net>
List-subscribe: <https://lists.sourceforge.net/lists/listinfo/xen-devel>, <mailto:xen-devel-request@lists.sourceforge.net?subject=subscribe>
List-unsubscribe: <https://lists.sourceforge.net/lists/listinfo/xen-devel>, <mailto:xen-devel-request@lists.sourceforge.net?subject=unsubscribe>
References: <E1AIHng-0003MI-00@xxxxxxxxxxxxxxxxxxxx> <E1AIOmB-0002CM-00@xxxxxxxxxxxxxxxxxxxx>
Sender: xen-devel-admin@xxxxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.4.1i
On Sat, Nov 08, 2003 at 08:48:59AM +0000, Keir Fraser wrote:
> 
> > > > Have you been using xen_read_console?  You should be able to
> > > > watch the other domain booting, and check that it comes up OK.

> > > I run it (in the background) but never see anything.  Even
> > > when I reboot, I don't get shutdown messages (they don't
> > > appear on the physical console).
> > 
> > Very odd. Any chance you can get a serial line on the system?
> > The other domain's boot messages should also come out on serial.

They do.  But the system unit is in another room, so it's
not too convenient to get these messages.  I'd be happiest
for them to go to a file!

> It sounds to me like a misconfigured domain 0 firewall. Can you send
> the output from 'iptables -L -v' and 'iptables -tnat -L -v' ?
> 
> If you do that just before and just after booting a new domain then
> that may allow us to see which rule is dropping the console UDP packets.

I'm finally picking this up again - sorry for not getting
right to it.  The problem we're trying to solve is that console
messages are going to the serial port, but not the
physical console or to the shell via xen_read_console.

I experiemented a lot, and this message was 1000 lines longer
with output from iptables etc.  Bottom line is this now works,
though I'm not 100% certain I can replicate all the differences.

Basically:
1) Reconfigure the default firewall rules to block nothing and
accept everything;
2) Reboot

There is still a very desirable feature: I'd *really* like
xenconsole messages from all domains to go to a file.

The basic setup I have for virtual domains required:
1) ln -s /dev/hdc /dev/cdrom_link   (or modify /etc/xen-mynewdom)
2) leave the CD-ROM in the drawer, but don't boot from it
3) boot to Xen (my new images, discussed earlier)
3a) run "xen_read_console &" as root, to see boot messages  
4) start new domains with xenctl

Steps 1 and 2 are not clear from the 1.0 README.CD.

I now have virtual domains booted and can access them.  I will send
another note describing what I'd like to do to get these living on the
real (non-ram) file system with NFS and shared /usr etc., but will
experiment more first.

Thanks!
  -- Greg




-------------------------------------------------------
This SF.Net email sponsored by: ApacheCon 2003,
16-19 November in Las Vegas. Learn firsthand the latest
developments in Apache, PHP, Perl, XML, Java, MySQL,
WebDAV, and more! http://www.apachecon.com/
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel