WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] transparant (secure) bridge

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] transparant (secure) bridge
From: "Jeroen Kleijer" <jeroen.kleijer@xxxxxxxxx>
Date: Tue, 8 Apr 2008 17:50:56 +0200
Delivery-date: Tue, 08 Apr 2008 08:51:34 -0700
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; bh=rSoTJKvFCX3GOBletj0nLG7wI5EQ3nwQk3fvTOy69HA=; b=xyAJrEXkd4m7+RQfgp2LsyIsT8jttmZUUchEH4BnJu/D48t9ZxZrMjS0pTJdrM6EOI7nkX9sbEtp61UzV3SXvlZPV28y7kLmbJX2lB8QN2pBCa6uc6aYR1fGSGeqA1/K731d9Xlxr4QDaWKMvOqgXF3TAB91DZbEaDSzlILOhdY=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=OOj0SIdtRYfQbE2n8eTKxgBXRmD+22TlrRzsq5/hilimitRvlWzBwSGcP8EQrm3w6Np114SwIShJjCbwsesiWrfkAV2Qx66KQIUHfVbJUwS/BLhuBkISCJHoZ1VSGtbMlvZSbop/VEBib0D7AlQJ2QnF/kbpOGeWXmhgVVCdi+E=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Hi all,

I've been reading up on the xen networking options / differences as
written in http://wiki.kartbuilding.net/index.php/Xen_Networking and
see a couple of examples that interest me like the (default) bridging
but also the routed networking.

However, the thing I'm most interested in would be transparant network
bridging like a firewall bridge where the bridging host (dom0) has no
exposed IP address to the outside world and is only accessible through
the console or a completely separate management interface (eth1, not
accessible from any of the domU's)

Since dom0 has no IP interface exposed to the outside but only acts as
a bridge from the outside to the domU's, that would make the dom0 a
bit more secure.

Would such a implementation be feasible or does the dom0 network
interface always have to have an IP stack for the bridging to work?

Regards,


Jeroen Kleijer

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>