On Tue, Dec 18, 2007 at 08:48:46PM +0100, ropers wrote:
just to give you a crazy example what people/vendors think is a
possible "security benefit":
some people have the idea to use virtualization on a central monster
firewall to segregate multiple departments on a single physical
device. this "firewall virtualization" feature is supported by
Cizzco-Eeeh and other vendors. this is just a scary useability feature
to give the admin the opportunity to offload some work to
customers/departments..
of course, it is a very bad idea from a security point of view; one
example of VM vulnerability was given by my early vic(4) driver which
caused segfaults of the GSX server host side.
i think it is much better, if not doing it correctly by using
distributed edge firewalls, to use pf anchors, tables, etc. to support
multiple firewall operators.
anyway, blah, there is a big controversy about VMs and Xen, but it
could be at least useful for things like testing, development, and
other edge cases.
reyk
| Mark Lord | 2.6.25-rc8: FTP transfer errors |
| Andrew Morton | echo mem > /sys/power/state |
| david | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
git: | |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| David Miller | [GIT]: Networking |
| Dushan Tcholich | Re: ksoftirqd high cpu load on kernels 2.6.24 to 2.6.27-rc1-mm1 |
