login
Header Space

 
 

Re: Xen status

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: ropers <ropers@...>
Cc: comfooc <comfooc@...>, <misc@...>
Date: Thursday, December 20, 2007 - 5:35 pm

On Tue, Dec 18, 2007 at 08:48:46PM +0100, ropers wrote:

just to give you a crazy example what people/vendors think is a
possible "security benefit":

some people have the idea to use virtualization on a central monster
firewall to segregate multiple departments on a single physical
device. this "firewall virtualization" feature is supported by
Cizzco-Eeeh and other vendors. this is just a scary useability feature
to give the admin the opportunity to offload some work to
customers/departments..

of course, it is a very bad idea from a security point of view; one
example of VM vulnerability was given by my early vic(4) driver which
caused segfaults of the GSX server host side.

i think it is much better, if not doing it correctly by using
distributed edge firewalls, to use pf anchors, tables, etc. to support
multiple firewall operators.

anyway, blah, there is a big controversy about VMs and Xen, but it
could be at least useful for things like testing, development, and
other edge cases.

reyk
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Xen status, ropers, (Tue Dec 18, 3:48 pm)
Re: Xen status, Reyk Floeter, (Thu Dec 20, 5:35 pm)
speck-geostationary