Re: OpenBSD firewalls as virtual machine ?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: OpenBSD Misc <misc@...>
Date: Friday, September 21, 2007 - 9:19 am

It sounds to me like the comments here are largely appropriate,
virtualizing firewalls in the limited context that has been explained
probably isn't a real good idea...at least due to perceived load.
Additionally, if there are that many fireuwalls being ran, instead of
numerous interfaces in a fewer number of machines, you're going to
continue to have problems being able to virtualize enough hardware
network interfaces.

However, I don't fully agree with the sentiment that running a firewall
in a virtual machine (let's be specific, VMWare ESX) guest environment.
I'm running my firewall on a ESX 3.0.2 guest, and it works perfectly
fine. That being said, you have to be aware of the VM configuraton.
The majority of vulnerabilities in VMWare are patchable (so yes, someone
needs to do maintenance), but are also issues that affect the VMKernel
or service console, and with careful planning, the vulnerabilities can
largely be prevented for being used as exploits on external interfaces.

And one final note...although I am a fan of virtualization (I work for
the company that owns VMWare), I really, really wish they did not have
so many freaking patches...

Kent Watsen wrote:

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OpenBSD firewalls as virtual machine ?, Josh, (Thu Sep 20, 9:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Die Gestalt, (Mon Sep 24, 8:56 am)
Re: OpenBSD firewalls as virtual machine ?, David Gwynne, (Mon Sep 24, 7:59 am)
Re: OpenBSD firewalls as virtual machine ?, Eduardo Tongson, (Sat Sep 22, 11:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Bryan Irvine, (Fri Sep 21, 7:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Kent Watsen, (Fri Sep 21, 8:07 am)
Re: OpenBSD firewalls as virtual machine ?, Scott Wells, (Fri Sep 21, 9:19 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Fri Sep 21, 10:52 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Sat Sep 22, 12:36 am)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Sat Sep 22, 10:53 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Sat Sep 22, 11:36 am)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 11:17 am)
Re: OpenBSD firewalls as virtual machine ?, Henning Brauer, (Sat Sep 22, 7:29 am)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Fri Sep 21, 3:29 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 5:15 pm)
Re: OpenBSD firewalls as virtual machine ?, Stuart Henderson, (Fri Sep 21, 3:51 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 5:16 pm)
Re: OpenBSD firewalls as virtual machine ?, Claudio Jeker, (Fri Sep 21, 6:34 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 8:06 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Sat Sep 22, 7:35 pm)
Re: OpenBSD firewalls as virtual machine ?, n0g0013, (Sat Sep 22, 8:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 7:10 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Fri Sep 21, 10:48 am)
Re: OpenBSD firewalls as virtual machine ?, Ted Unangst, (Fri Sep 21, 4:28 pm)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 11:09 am)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 8:58 am)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Thu Sep 20, 9:52 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Sat Sep 22, 7:45 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Fri Sep 21, 2:18 am)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 4:03 am)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 9:35 pm)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Thu Sep 20, 9:53 pm)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 10:15 pm)