This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


RE: [Xen-users] virtual mirror port on xen

To: "Michael Stegk" <lists.michael@xxxxxxxxx>, <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: RE: [Xen-users] virtual mirror port on xen
From: "James Harper" <james.harper@xxxxxxxxxxxxxxxx>
Date: Tue, 29 Jun 2010 16:49:14 +1000
Delivery-date: Mon, 28 Jun 2010 23:50:56 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <DB51EA8B-AC8E-4092-B532-6ED0F21C3ABE@xxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <DB51EA8B-AC8E-4092-B532-6ED0F21C3ABE@xxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcsXU/HSbl9K/lIdRwmANjwHZjFmwAAAPeuw
Thread-topic: [Xen-users] virtual mirror port on xen
> I try to get an Snortbased IDS running on a DomU, the IDS need to be
> able to intercept all packets regarding communication between DomUs
> and between the Dom0 and the physical network. It is obviously
> importend that other DomUs receive only their dedicated packets. This
> is pretty much known as a mirror port on "normal" switches.

You could try vswitch, I think it has a mirror port option.

I think the sort of things you are trying are going to give you a
headache :)


Xen-users mailing list

<Prev in Thread] Current Thread [Next in Thread>