WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Xen

xen-users

[Top] [All Lists]

Re: [Xen-users] Ideal(istic) Xen firewall design

To: "Dirk H. Schulz" <dirk.schulz@xxxxxxxxxxxxx>
Subject: Re: [Xen-users] Ideal(istic) Xen firewall design
From: Marcus Brown <marcusbrutus@xxxxxxxxxxxxxxxx>
Date: 2005年8月15日 16:35:20 +1000
Cc: Mike Tierney <miket@xxxxxxxxxxxxxxxx>, xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: 2005年8月15日 06:39:45 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <43002F9D.7000802@xxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <200508142130.j7ELUZ7k011456@xxxxxxxxxxxxxxxx> <43002F9D.7000802@xxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Debian Thunderbird 1.0.2 (X11/20050602)
Hi Dirk and Mike,
Dirk H. Schulz wrote:
> Hi Mike,
>
> Mike Tierney schrieb:
>
>> But it is still tempting to just do away with the seperate firewall vm
>> and
>> do all the firewalling in Dom0!
>> 
>>
Having got my Firewall domain working reasonably well I'd have to say that
I wouldn't go back! :) Extremely handy being able to create a Firewall,
restart it, swap in another version ... all without having to restart
my other domains!
> There is one more reason to put the firewall into a guest system: The
> guests use the smaller kernels (without hardware support etc.), so there
> is less possibility of kernel bugs that can be used to crack the
> firewall. It is more of a statistic perspective but with firewalling
> everything should be used to avoid leaks, I think.
>
The firewall domain _does_ have hardware support (ie. network cards),
so I'm not sure if your logic applies.
(ie. Firewall still has DMA)
But, still, everything else is/can be virtualised, so it's still a step
up from a dom0 (IMHO).
Marcus.
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>
Previous by Date: Re: [Xen-users] Ideal(istic) Xen firewall design , Dirk H. Schulz
Next by Date: Re: [Xen-users] Failover , Matthijs ter Woord
Previous by Thread: Re: [Xen-users] Ideal(istic) Xen firewall design , Dirk H. Schulz
Next by Thread: Re: [Xen-users] Ideal(istic) Xen firewall design , Martin Maney
Indexes: [Date] [Thread] [Top] [All Lists]

Copyright ©, Citrix Systems Inc. All rights reserved. Legal and Privacy
Citrix This site is hosted by Citrix

AltStyle によって変換されたページ (->オリジナル) /