[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] pfSense HVM





actually, i use pfSense in hvm quite a while... it works. recently i tried to get pfSense in pv, but that needs to be polished some time before it is ready to use. (it works, but it is half broken that way and i spent the whole day yesterday to get a clear view on that problem).
That's good that it works well in HVM. What kind of throughput can you get? My co-lo is giving me a 100Mbit connection, thing Xen can handle that?

make sure, you can access that dom0 in event of emergency. If anything happens to your pfsense, which is possible, you probably can't access your dom0 anymore and are stuck and thats probably not what you want.
This is a really good point, and I'm not sure what to do in this case. The only thing I can think of, is to give the 2nd physical NIC on the server access to the Dom0 directly (bypassing the pfSense firewall DomU), however I'm not sure if my co-lo can provision this without extra costs...

btw, you don't need to passthrough your nic for that behavior. In a bridged setup you just have to leave your bridge interface to the outside without an ip address.
Since the NIC will be the physical interface for the WAN, I thought I would use PCI Passthrough for extra security? So that the Dom0 has *no access* to the physical NIC? Or am I incorrect?


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.