WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Best practice for firewall in domU

To: Xen-Users <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: Re: [Xen-users] Best practice for firewall in domU
From: Christian <chris@xxxxxxxxxxxxxxxx>
Date: Thu, 09 Nov 2006 19:14:10 +0100
Cc: Alan Murrell <alan@xxxxxxxxxx>
Delivery-date: Thu, 09 Nov 2006 10:14:36 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Thunderbird 1.5.0.7 (X11/20060911)
Hi Alan

I saw this thread 
(http://lists.xensource.com/archives/html/xen-users/2006-10/msg00071.html) and 
still have some questions.

>Hi Darrin,
>
>On Monday 02 October 2006 11:09, Darrin Wortlehock wrote:
>>/ I am currently assuming I would want two bridges defined in the dom0,/
>>/ one for the public IP's and one for the private network.  If this is/
>>/ the case, how should I go about creating the bridges in a dom0 that/
>>/ has no ethernet adapter? The private network's bridge would want to/
>>/ be accessible from dom0, the DMZ bridge definitely not./
>
>Create the necessary additional interfaces/bridges in Dom0 using the dummy 
>interface, then export them to the firewall DomU.  The firewall DomU will see 
>them as network interfaces.


Can you give me some more info about how to create a dummy interface?
And how to export them to the firewall DomU?

I moved via pciback all real Nics to firewall DomU. There they work
so Dom0 does not have any nic anymore.
How to enable only networking between firewall domU and dom0.

Any hint would be apreciated.

Thanks

Chris


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>
  • Re: [Xen-users] Best practice for firewall in domU, Christian <=