[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [Xen-users] Xen Security
On Fri, Jul 16, 2010 at 3:32 PM, Jonathan Tripathy
<jonnyt@xxxxxxxxxxx> wrote: ----------------------------------------------------------------------------------------------------------------------------------------------------------- Hi Fajar, I am using CentOS 5.5 with the stock Xen kernel that came with it, however I'm using Xen 3.4.2 from gitco.de - think this is safe enough? I'm fairly sure that my network setup is secure. I'm using iptables to prevent IP spoofing, and using ebtables to prevent MAC spoofing. A firewall DomU (pfsense) has WAN, LAN, DMZ and PUBLIC interfaces. WAN and PUBLIC are bridged (For the customers' public VMs). The DMZ subnet only allows certain needed incoming ports from the internet (via NAT port forwarding), and outbound is also restricted to what's only needed. The LAN subnet doesn't allow any incoming ports from the internet. Ports between DMZ and LAN are also only open on a "need to" basis. I've been told that since my Public and DMZ bridges in the Dom0 have no IP addresses, it is impossible for the Dom0 to route traffic between them without going through the firewall DomU. What you think? Thanks _______________________________________________ Xen-users mailing list Xen-users@xxxxxxxxxxxxxxxxxxx http://lists.xensource.com/xen-users
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |