WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Giving a domU direct access to a NIC

To: "Nemeth, Tamas" <nice@xxxxxxxxxxxxxxx>
Subject: Re: [Xen-users] Giving a domU direct access to a NIC
From: "Antoine Benkemoun" <antoine@xxxxxxxxxxxxx>
Date: Sat, 20 Sep 2008 12:44:19 +0200
Cc: Xen Users <xen-users@xxxxxxxxxxxxxxxxxxx>
Delivery-date: Sat, 20 Sep 2008 03:45:02 -0700
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:sender :to:subject:cc:in-reply-to:mime-version:content-type:references :x-google-sender-auth; bh=1XAkth6G9pwVtINu1VS5bKI85npcKIlqnZEwePaEtI4=; b=vpaE4fQC5PTNWV1D8vZI5B2YGZlGgFiGhKpOA3Xt8a4nOfN2x0AhaJCHX1dAQa8EJ9 NDVmUDfuCVy5t46aPVSXpTikjOK/UEjNYv6NJwgmB6MIhd70Wn3irNB7qV+5zFS9jL1+ vsdi5/D+t6Yv17XOspeith98a1yOm3ryDmizE=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:sender:to:subject:cc:in-reply-to:mime-version :content-type:references:x-google-sender-auth; b=JJAB3rcR40m9lG2J2jdvV/kfPyFuYRgin6/Di6+mi6a0vntGrSUbOWtFr+QJQUAJ3q 0YQmmFSptkrwxFK+pVSRqvZ1BxHrHMlOXNneMB1wWuSCWsyJeZKYKUC64Ipcb0iOy8xE yLSd5dXrq++L/Z2ZTE1+tL7CFmYFt+ndfT50s=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <fc1cbedb0809190616m2fa992dfwbafa4543b5f2a2e4@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <fc1cbedb0809190138g71df035n7eb229bda2cf5cb9@xxxxxxxxxxxxxx> <1221815374.4386.32.camel@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> <fc1cbedb0809190616m2fa992dfwbafa4543b5f2a2e4@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Just another question, wouldn't it be possible to do this with ebtables ? For example, if I bridge the snort interface to the regular NIC and then I forward all the packets to this NIC, would i be able to use ebtables or something along these lines to send the packets to the snort interface ?

Thanks for your help,

Antoine

On Fri, Sep 19, 2008 at 3:16 PM, Antoine Benkemoun <antoine@xxxxxxxxxxxxx> wrote:
Thanks very much ! I'll have a look at that



On Fri, Sep 19, 2008 at 11:09 AM, Nemeth, Tamas <nice@xxxxxxxxxxxxxxx> wrote:
2008. 09. 19, péntek keltezéssel 10.38-kor Antoine Benkemoun ezt írta:

> I don't really know how Xen networking works,
http://wiki.xensource.com/xenwiki/XenNetworking
http://ebtables.sourceforge.net/br_fw_ia/br_fw_ia.html



> but is it possible to give a domU direct access to a NIC ?

It's possible to give PCI devices (including ethernet cards ;) to domUs.
I haven't ever tried this, but you may read:
http://www.novell.com/communities/node/2880/assign-dedicated-network-card-or-pci-device-xen-virtual-machine



> Or at least give it enough access so that it can see packets that are
> not for the domU originally.

I'm afraid not.





--
Antoine Benkemoun
Tel : 03.51.53.57.00
Port : 06.32.88.59.35



--
Antoine Benkemoun
Tel : 03.51.53.57.00
Port : 06.32.88.59.35
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>