WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Question about using Xen in a periphery firewall/router

To: Simon Hobson <linux@xxxxxxxxxxxxxxxx>
Subject: Re: [Xen-users] Question about using Xen in a periphery firewall/router scenario
From: Sanjay Arora <sanjay.k.arora@xxxxxxxxx>
Date: Sun, 23 Aug 2009 00:31:50 +0530
Cc: xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Sat, 22 Aug 2009 12:02:36 -0700
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=C7ANyjZrzMSnF1U9x8SrcJHVYaXyooOJXeuZ7WNLWd0=; b=TNGKfcOB/SbwkynJsvh1tjud1383oONGUG8i0xVZ78Kog9ZHxLYM0cZQUP6GkXPLHq zkt4rzKudBP8GRJq7uis7bUMdv1u2yqa7AokXBIvbjNi4qP+RfQV/e19jMd0ynYLCXAT gkyMR1+reHC0NBiHtDYH1IWczuNK5XScFDqJU=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; b=wELbyVXtzevoVaoXfPqcTrUa/fYMR/Reu5SHXQKT8WzJ+8wSKUcAkyCYYl3RTrQg7H WJU3gAnz6r17QaAvfpe9kHg2AGiCJPORwMR9l8jPrp+Pd5Vs1t7nQesvap72blqPs46N 4eT7h2B/BhPSbebq2RU7jFLlpZqH+yAscc6Pk=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <a0624081cc6b2f34a9625@xxxxxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <7e41ba8f0908200433m6f6feb1eq84ebda1bc65b9b8b@xxxxxxxxxxxxxx> <a0624081cc6b2f34a9625@xxxxxxxxxxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
On Thu, Aug 20, 2009 at 6:13 PM, Simon Hobson<linux@xxxxxxxxxxxxxxxx> wrote:

>
> The approach I've used at home is to hide a network card from Dom0 (see
> pic-back.hide) and pass it through to a DomU which then sees it as a native
> interface. I then run a firewall in the DomU and the outside traffic does
> NOT go through Dom0.  The route for packets is then :
>
> real i/f -> DomU (firewall) -> VIF -> int bridge [ Dom0 | VIF -> DomU ]
>
>

Can you advise hoe to set this up?

Thanks.
Sanjay.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users