[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Xen-users] If Dom0 was compramised


  • To: "Fajar A. Nugraha" <fajar@xxxxxxxxx>
  • From: "Ian Tobin" <itobin@xxxxxxxxxxxxx>
  • Date: Thu, 20 May 2010 11:13:14 +0100
  • Cc: Xen User-List <xen-users@xxxxxxxxxxxxxxxxxxx>
  • Delivery-date: Thu, 20 May 2010 03:14:14 -0700
  • List-id: Xen user discussion <xen-users.lists.xensource.com>
  • Thread-index: Acr4BM0SFMz+kd3TSOGznhe3eOClCgAACrzg
  • Thread-topic: [Xen-users] If Dom0 was compramised

Yes im using bridged.

Odd, so you can create any ip tables rules and it should not affect
domUs?

Ian



-----Original Message-----
From: Fajar A. Nugraha [mailto:fajar@xxxxxxxxx] 
Sent: 20 May 2010 11:11
To: Ian Tobin
Cc: Xen User-List
Subject: Re: [Xen-users] If Dom0 was compramised

On Thu, May 20, 2010 at 5:06 PM, Ian Tobin <itobin@xxxxxxxxxxxxx> wrote:
> Curious, what would be the best way to secure the Dom0.
>
> Ive tried iptables before but then prevented access to the DomUs.

Depends on your setup. If you use bridge networking, and
/proc/sys/net/bridge/bridge-nf-call-iptables is 0 (which is 1 by
default), domU traffic should be unaffected by dom0's iptables.

-- 
Fajar



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.