Xen 
 
Home About Xen.org Xen Xen Summit Wiki Mailing List Bug Tracker Xen Downloads
 
   
 

xen-users

[Xen-users] Re: Live Migration Config

Matthew Alton wrote:
This is not good. I'm going to have a devil of a time selling this into enterprises of any size. Are there any plans to provide filtering rules, authentication, authorization facilities in the works? Any bolt-ons?

Use iptables to prevent the dom0 from engaging in any communication except over a VPN. That way you have the VPN's authentication and encryption facilities available, and keep untrusted boxen away.

(OpenVPN is a hammer I'm quite fond of, so I see a lot of nails).


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users