[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] Multiple VMs - one static routable IP address


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: Nico Kadel-Garcia <nkadel@xxxxxxxxx>
  • Date: Fri, 18 May 2007 10:55:10 +0100
  • Delivery-date: Fri, 18 May 2007 02:51:10 -0700
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:content-type:content-transfer-encoding; b=K8tTgUt+K2S7nNJPz0k88K//+Jbm91uBwPv1hkcVwNMn8WRuBDx9bhPyLOK3gUbQTzAuZkvbhI9lmsQkcqLcU0NiK3TOLkPr9h5SjykpuYrL+WEkEvTxjurD+w0DSjOMB2IVSiraclAIz+lHN/HWlBL8oCIMuMI+VBcrnAF5638=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Alex Samad wrote:
On Thu, May 17, 2007 at 10:24:24PM -0500, cyber@xxxxxxxxx wrote:

Originally I was planning on putting all my own personal websites and email on Domain-0, as well as an iptables based firewall. Having read more, seems like the recommendation is to keep Domain-0 behind a DomU where the firewall runs. Makes sense, and doesn't seem difficult to do... just a new paradigm for me. I've always only had one server, and it did everything and anything. I love the idea of breaking it all up from a security and manageability standpoint... just not sure what to do about getting all the bits to the right VMs that need to be routed correctly.

if its for security of apps, why not look at chroot ?

chroot for OpenSSH has never been well-supported. (I used to be the maintainer of that add-on functionality, and it remains rejected by the core authors to this day, much to my lament.) WebDAV over HTTPS works well for upload/download sites, and avoids the shell access and local account problems of SSH.

I'm not a believer in external, hardware firewalls, to avoid the complexities and difficulties of maintaining my own software ones.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.