[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] Network isolation - PCI passthrough question



On Monday 20 December 2010 15:08:19 Jean Baptiste FAVRE wrote:
> Hello,
> I thinking about using PCI passthrough to dedicated a domU as firewall.
> 
> I understand PCI passthrough concept. When done, my domU will see
> network card and the dom0 won't any more. So I'll be able to filter all
> trafic from outside, since it will go through network domU.
> 
> Then, how will I be able to connect other domU (and maybe dom0) to the
> network domU ?
> 
> In a normal way, creating domU makes dom0 creating vif interfaces and
> bridge (in my configuration) it. But once netowkr will be isolated in a
> specific domU, dom0 won't be able to interact with it, will it ?
> 
> Any link/help/explanation appreciated.
> 
> Regards,
> JB

I actually do it this way. All the network devices are exported to my firewall-
domain and I can still access the dom0 (where the Firewall allows it)

Have a look at the "dummy" network interface. It works "just" like a normal 
NIC, eg. you can assign it an IP and you can add it to a bridge.

--
Joost

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.