WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] iptables, firewall into Dom0

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] iptables, firewall into Dom0
From: Sébastien CRAMATTE <s.cramatte@xxxxxxxxxx>
Date: Sat, 28 Oct 2006 17:40:25 +0200
Delivery-date: Sat, 28 Oct 2006 08:40:57 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Organization: Zen Soluciones
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Thunderbird 1.5.0.7 (Windows/20060909)
Hello

I've setup Xen using vlan. I've different bridge per vlan
Each VM have it's own iptables  script 
I've got various type of VM  : http, ldap, mysql, nagios, ...

My question is how can I protect the Dom0 without block all the traffic
from DomU ...
I require restrictive rules with at least these :

INPUT:
ssh (tcp)
snmp (udp)
snmptrap (udp)
ping (icmp)

OUTPUT
http  (tcp)
ssh  (tcp)
dns  (udp)


Regards



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>