[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] transparant (secure) bridge


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: "Jeroen Kleijer" <jeroen.kleijer@xxxxxxxxx>
  • Date: Tue, 8 Apr 2008 17:50:56 +0200
  • Delivery-date: Tue, 08 Apr 2008 08:51:34 -0700
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=OOj0SIdtRYfQbE2n8eTKxgBXRmD+22TlrRzsq5/hilimitRvlWzBwSGcP8EQrm3w6Np114SwIShJjCbwsesiWrfkAV2Qx66KQIUHfVbJUwS/BLhuBkISCJHoZ1VSGtbMlvZSbop/VEBib0D7AlQJ2QnF/kbpOGeWXmhgVVCdi+E=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Hi all,

I've been reading up on the xen networking options / differences as
written in http://wiki.kartbuilding.net/index.php/Xen_Networking and
see a couple of examples that interest me like the (default) bridging
but also the routed networking.

However, the thing I'm most interested in would be transparant network
bridging like a firewall bridge where the bridging host (dom0) has no
exposed IP address to the outside world and is only accessible through
the console or a completely separate management interface (eth1, not
accessible from any of the domU's)

Since dom0 has no IP interface exposed to the outside but only acts as
a bridge from the outside to the domU's, that would make the dom0 a
bit more secure.

Would such a implementation be feasible or does the dom0 network
interface always have to have an IP stack for the bridging to work?

Regards,


Jeroen Kleijer

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.