WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

RE: [Xen-users] XCP Xen Cloud Control System ver 0.3 released!

On Tue, May 25, 2010 3:24 pm, Jonathan Tripathy wrote:
> You could try this:
> http://www.standingonthebrink.com/index.php/ipv6-ipv4-and-arp-on-xen-for-vps/
>
> Don't know if it will stop DHCP broadcasts, but maybe...

That article is more relevant to vanilla Xen with the linux bridge.  It
would stop a VM from assigning itself the IPv4 or v6 address of another
VM.  DHCP requests are broadcast so it would be valid for a VM to see it
and nothing would stop it from replying.

XCP uses openvswitch, so you would need to add some flow rules to ovs. One
to stop the IP spoofing and one to specify which hosts (and possibly
ports) are allowed to answer DHCP requests.  I've been playing with it on
and off for a while now.  I'll crack it, I'm sure, but haven't yet.

Openvswitch looks really powerful or at least has potential to be but
there isn't much documentation which is why I am struggling a bit.


Cheers,

Matt.



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users