[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-users] Firewalling Xen?
On Wed, Dec 17, 2008 at 12:06 AM, Andris <andris@xxxxxxxx> wrote:
Hi! So you have the DomU1's IP address exposed to the outside and then have one of it's network interfaces on the internal private networks bridge? I'd assume this means that the DomU1's other network interface would be added to the eth0 bridge that peth0 resides on? I'm not sure I like the idea of Dom0 sitting there unprotected. Let's not forget that if another machine anywhere on the real network were exploited the Dom0 is a sitting duck. The consequences of Dom0 falling are huge.. You could just keep it that same way and put a firewall on Dom0 anyway because what do you really want to allow in since the router is really DomU1? I was thinking though of having the traffic come in eth0 and have Dom0's firewall forward everything to the first DomU which would then do all the real filtering and NAT. I only have one external IP address to use. I'm a bit worried about speed though since I'm filtering everything twice. Grant _______________________________________________ Xen-users mailing list Xen-users@xxxxxxxxxxxxxxxxxxx http://lists.xensource.com/xen-users
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |