From: "B.G. Bruce" <bgb@nt-nv.com>
To: Mark Williamson <maw48@cl.cam.ac.uk>
Cc: xen-devel <xen-devel@lists.sourceforge.net>
Subject: Back end domains : input desired
Date: Mon, 24 Jan 2005 12:09:34 -0400 [thread overview]
Message-ID: <1106582974.4743.213.camel@master.vms.security> (raw)
In-Reply-To: <200501221446.12675.maw48@cl.cam.ac.uk>
What I'd LOVE to achieve with XEN (for security reasons) is the
following:
DOM0: minimal linux install with LVM2 primarily for backending the ide
disks.
BE_NIC_0: Back end NIC_0 domain (bridge) with minimal linux install -
no ip address assigned - using ebtables to filter/protect
BE_NIC_1: Same as BE_NIC_0 only for NIC_1
BE_VNIC_2: Back end for a "virtual nic"/bridge for DomU to DomU
communication (DMZ).
BE_MGMT: firewall config/mgmt console (xwindows) (preferred x
displaying (direct) through AGP on console - is this possible) and
ntp/clock sync (can this happen here or does it have to happen on
DOM0?).
Various front end DomU's: for router/fw and various application layer
gateways.
My idea here is to be able to isolate the components into minimal
operating environments allowing for specific need/application to be
rebooted without having to reboot the entire box should that particular
component be DoS'ed.
Your thoughts on this setup would be appreciated (also you can see that
having a socket interface rather than an ip interface for XEND would be
of GREAT advantage).
Now, I've tried setting this up but I'm running into some confusion
here.
1) I only seem to be able to compile the actual NIC drivers with DOM0
(e100/e1000/3c95x, etc). Is this where I should be compiling them even
though the NIC's will be used in another DOM? If not, how do I go about
compiling the drivers for the BE DOM'S? (they don't show up as options -
yes, I do have XEN_PHYSDEV_ACCESS and XEN_NETDEV_BACKEND enabled.
2) Even with pci_dom0_hide=(01,01,0)(02,00,0) as part of my grub.conf
(for the startup of xen.gz), I still see these devices under DOM0, is
this normal? lspci shows the devices as 0000:01:01.0 and 0000:02:00:0.0)
respectively. Are my parameters to pci_dom0_hide correct?
3) Should I be using stable, testing or unstable for this? NOTE:
stable and testing both are unable to attach xen console to ttyS whereas
unstable works correctly for this.
4) It would be preferred to run X in a domain separate from Dom0, but
still be accessible for use on the local console without having to
install X and a VNC client in DOM0. Is this possible, or am I just
dreaming here?
Regards,
B.
-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
next prev parent reply other threads:[~2005-01-24 16:09 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-01-19 21:21 Must have been asked before, but I can't find the solution Ian Pratt
2005-01-19 21:32 ` B.G. Bruce
2005-01-19 21:51 ` Kip Macy
2005-01-19 21:52 ` Felipe Alfaro Solana
2005-01-19 22:08 ` B.G. Bruce
2005-01-19 22:13 ` Kip Macy
2005-01-20 13:01 ` Mark Williamson
2005-01-20 15:30 ` B.G. Bruce
[not found] ` <200501210044.03264.maw48@cl.cam.ac.uk>
[not found] ` <1106284353.4743.46.camel@master.vms.security>
[not found] ` <200501221446.12675.maw48@cl.cam.ac.uk>
2005-01-24 16:09 ` B.G. Bruce [this message]
2005-01-24 16:18 ` Back end domains : input desired Mark A. Williamson
2005-01-24 16:36 ` B.G. Bruce
2005-01-24 16:50 ` Tobias Hunger
2005-01-24 17:03 ` Jan Kundrát
2005-01-24 17:06 ` Mark A. Williamson
2005-01-24 17:17 ` Andrew Warfield
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1106582974.4743.213.camel@master.vms.security \
--to=bgb@nt-nv.com \
--cc=maw48@cl.cam.ac.uk \
--cc=xen-devel@lists.sourceforge.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.