[Shorewall-users] Comparing approcahes to Shorewall firewall on a Xen server. Any experience or recommendations?

2015-04-21 Thread aleph2
Hi My office is getting a Xen on linux server donated. Looks like I'm on the hook to get it up and running. Been reading and testing bits and pieces. Most seem pretty straight forward. I have a question about using Shorewall on the Xen machine to provide firewall for the machine Hosts, the

Re: [Shorewall-users] Comparing approcahes to Shorewall firewall on a Xen server. Any experience or recommendations?

2015-04-21 Thread Roberto C . Sánchez
On Tue, Apr 21, 2015 at 07:39:37PM +, ale...@vfemail.net wrote: > > IIUC that's one of three ways I can think of to handle the firewall, > > (1) 2 ethernet interfaces in the Dom0 host, shorewall on the Dom0 > (2) 1 ethernet interfacs in the Dom0 host, 1 eth intfc in a DomU guest, > shorewall

Re: [Shorewall-users] Comparing approcahes to Shorewall firewall on a Xen server. Any experience or recommendations?

2015-04-21 Thread aleph2
Hi Roberto On 2015-04-21 19:49, Roberto C. Sánchez wrote: > Personally, I like the approach of running Shorewall inside of each > domU. But then, I employ the "every node on the network is untrusted > by > default" approach. I have all the physical interfaces in the dom0 > (with > the dom0 onl

Re: [Shorewall-users] Comparing approcahes to Shorewall firewall on a Xen server. Any experience or recommendations?

2015-04-21 Thread Tom Eastep
On 4/21/2015 12:39 PM, ale...@vfemail.net wrote: > Hi > > My office is getting a Xen on linux server donated. Looks like I'm on > the hook to get it up and running. > > Been reading and testing bits and pieces. Most seem pretty straight > forward. > > I have a question about using Shorewall