All of lore.kernel.org
 help / color / mirror / Atom feed
* Bridging firewall?
@ 2005-01-21 10:49 Nicholas Lee
  2005-01-21 13:55 ` Grzegorz Milos
  0 siblings, 1 reply; 14+ messages in thread
From: Nicholas Lee @ 2005-01-21 10:49 UTC (permalink / raw)
  To: xen-devel


Is it possible with Xen to construct something like the following scenario.

Free/NetBSD (*) domU server running pf or Linux/iptables, acting as a
routing or bridging firewall for all the other domU guests? Further more
create virtual DMZ and internal services.

You'd probably keep the dom0 instance otherside this setup, with its own
filtering arrangement.


For instance, you have a subnet 192.168.1.0/24.  Put the dom0 on 192.168.1.254.
Have the firewall router domU running on 192.168.1.1 and acting as the
gateway for all the other machines on the subnet.


(*) This is my dream, using pf for security and debian for serving the
applications. ;)

Nicholas


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl

^ permalink raw reply	[flat|nested] 14+ messages in thread
* RE: Bridging firewall?
@ 2005-01-23 23:15 Ian Pratt
  2005-01-26 21:11 ` Matthieu PATOU
  0 siblings, 1 reply; 14+ messages in thread
From: Ian Pratt @ 2005-01-23 23:15 UTC (permalink / raw)
  To: Matthieu PATOU, xen-devel

 > In order to feel secure i've activated the antispoof options, 
> but as it was
> broken for me i tweak a little the rules ... if someone is 
> intrested i can post
> my script and give some explanations.

That would be useful.

Thanks,
Ian


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl

^ permalink raw reply	[flat|nested] 14+ messages in thread
* RE: Bridging firewall?
@ 2005-01-26 21:56 Ian Pratt
  2005-01-26 22:06 ` Matthieu PATOU
  0 siblings, 1 reply; 14+ messages in thread
From: Ian Pratt @ 2005-01-26 21:56 UTC (permalink / raw)
  To: Matthieu PATOU; +Cc: xen-devel


Are you sure your new scripts actually still implement the antispoof
feature of ensuring that the guest can only send packets using its
allocated IP? It looks to me like they're too lax.

Ian

> -----Original Message-----
> From: Matthieu PATOU [mailto:matxen@matws.net] 
> Sent: 26 January 2005 21:12
> To: Ian Pratt
> Cc: xen-devel@lists.sourceforge.net
> Subject: Re: [Xen-devel] Bridging firewall?
> 
> On Sun, 23 Jan 2005 23:15:29 -0000
> "Ian Pratt" <m+Ian.Pratt@cl.cam.ac.uk> wrote:
> 
> >  > In order to feel secure i've activated the antispoof options, 
> > > but as it was
> > > broken for me i tweak a little the rules ... if someone is 
> > > intrested i can post
> > > my script and give some explanations.
> > 
> > That would be useful.
> > 
> See the attached files, in order to work i put some rules :
> vifx.0 must be bridged to xen-br0 (it correspond to the 
> output of the firewall)
> in order to be really accessible (some iptables rules are 
> juste added line 79
> and 80 for vifx.0 and not for other vif).
>  
> 


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2005-01-26 22:06 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-01-21 10:49 Bridging firewall? Nicholas Lee
2005-01-21 13:55 ` Grzegorz Milos
2005-01-21 14:11   ` Felipe Alfaro Solana
2005-01-21 15:02     ` Jan Kundrát
2005-01-21 15:08       ` Jan Kundrát
2005-01-21 15:30         ` Georgios Portokalidis
2005-01-23 23:12   ` Matthieu PATOU
2005-01-24  1:21     ` Nicholas Lee
2005-01-25 17:27       ` Matthieu
2005-01-25 19:42         ` Nicholas Lee
  -- strict thread matches above, loose matches on Subject: below --
2005-01-23 23:15 Ian Pratt
2005-01-26 21:11 ` Matthieu PATOU
2005-01-26 21:56 Ian Pratt
2005-01-26 22:06 ` Matthieu PATOU

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.