[Xen-users] Virtual Air Gap

Is a virtual air gap possible where dom0 is not connected to theÂÂÂÂÂÂÂÂÂÂÂÂÂ
internet but domU is? For instance if I set dev eth0 down, is thereÂÂÂÂÂÂÂÂÂÂ
a configuration where domU can still connect to the internet? If so,ÂÂÂÂÂÂÂÂÂ
what additional steps should I take when setting up xenbridge, or isÂÂÂÂÂÂÂÂÂ
a bridge needed at all? If not, can I pass through the NIC to someÂÂÂÂÂÂÂÂÂÂÂ
domU and make a xenbridge between the other domUs, keeping dom0
offline? I know it's possible to keep a domU offline, but if dom0 is
compromised, is an attack on that domU easier?
