WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Xen, HVM guest won't start without VNC=1

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] Xen, HVM guest won't start without VNC=1
From: jim burns <jim_burn@xxxxxxxxxxxxx>
Date: Tue, 25 Dec 2007 14:25:26 -0500
Delivery-date: Tue, 25 Dec 2007 11:26:01 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <06F00D752AB28449913615FC4CC4DD14842C28@xxxxxxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <475ED56B.7432.000D.0@Adsl> <20071212073249.GB9721@xxxxxxx> <06F00D752AB28449913615FC4CC4DD14842C28@xxxxxxxxxxxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.6 (enterprise 0.20071123.740460)
On Wed December 19 2007 5:45:10 pm Norton, Jerry wrote:
> kernel = '/usr/lib/xen-3.0.3-1/boot/hvmloader'
> builder = 'hvm'
> device_model='/usr/lib/xen-3.0.3-1/bin/qemu-dm'
> memory = '256'
> disk = [
> 'phy:/dev/xendisks/base_deb,ioemu:hda,w','phy:/dev/cdrom,hdc:cdrom,r' ]
> name = base_deb'
> vif = ['type=ioemu,bridge=xenbr0,mac=00:19:c0:a8:01:c9']
> boot='c'
> vnc=1
> vncviewer=0
> vncunused=0
> vncdisplay=2
> vnclisten='0.0.0.0'
> serial='pty'

When Igor says 'bind vnc to localhost', the simple way to do that is 
vnclisten='127.0.0.1'. Then only someone who has ssh access to the xen server 
can get a vnc window. He's also right that either sdl or vnc must =1. That 
bit me recently when vnc was failing. And his iptables trick is also nice. 
Note that the iptables '--dport' option accepts a port range, as in '--dport 
5900:5910', etc. 

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users