|  |  | 
  
    |  |  | 
 
  |   |  | 
  
    |  |  | 
  
    |  |  | 
  
    |   xen-users
Re: [Xen-users] Ideal(istic) Xen firewall design 
| Hi Dirk,
Dirk H. Schulz wrote:
> Hi Marcus,
> 
> thanks for so much info!
> 
> Just a short question before I start digging into your configs: What do
> you gain by running the firewall inside a privileged guest system
> instead of inside dom0?
> 
It's modular, restartable, replaceable, ...
(ie. I can reboot the firewall without rebooting all the domUs)
errr
oh, and someone gaining root access to the firewall won't be able to
play with xend, or the filesystems of the domUs.
I'm sure there are other good reasons :)
I've got all my domains (except dom0) on lvm+raid so snapshotting is a
great way of testing and making backups.
This is just the start, though ... more ideas being worked on atm.
Marcus.
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
 | 
 
| <Prev in Thread] | Current Thread | [Next in Thread> |  | 
[Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Andreas Seuss
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Message not availableRe: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
Re: [Xen-users] Ideal(istic) Xen firewall design,
Marcus Brown <=
Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
RE: [Xen-users] Ideal(istic) Xen firewall design, Mike Tierney
Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
Re: [Xen-users] Ideal(istic) Xen firewall design, Dirk H. Schulz
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Martin Maney
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Marcus Brown
Re: [Xen-users] Ideal(istic) Xen firewall design, Mark Williamson
 |  |  | 
  
    |  |  |