[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Xen-users] latest GPLPV drivers 0.10.0.86 and microsoft.com



But firewalling Dom 0 doesn't affect the VMs?  

And also if you did that you might not want to block certain ports as it
could be different on every VM.

BTW what is the best way of firewalling a Dom 0 built from the lenny
debs?

Thanks

Ian



-----Original Message-----
From: James Harper [mailto:james.harper@xxxxxxxxxxxxxxxx] 
Sent: 08 September 2009 14:03
To: Ian Tobin; Fajar A. Nugraha
Cc: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: RE: [Xen-users] latest GPLPV drivers 0.10.0.86 and
microsoft.com

> 
> In the end this turned out to be some worm getting onto the VPS before
> we had chance to enable the firewall so now we are building the images
> offline, enabling the firewall and putting them on the net.
> 
> Very strange how quickly it got infected but lessons learned.
> 
> Big thanks for James and Fajar for the advice.
> 
> On another note we cant put a perimeter firewall in place as the
servers
> are on the internet in the datacenter.
> 

You could firewall in Dom0 though.

Here (http://isc.sans.org/diary.html?storyid=7093&rss) is another good
reason why you should firewall early and firewall often :)

James



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.