www.fridu.net

  • Increase font size
  • Default font size
  • Decrease font size

Xen mini-ISP architecture - Zones Security Model

Print
Article Index
Xen mini-ISP architecture
Setting Basic Infrastruture
Installing a new VM
Network Infrastructure
Zones Security Model
Quick Start
Bugs, New Feature
All Pages

Security

The chapter describe Fridu reference architecture security model, unfortunatly the way iptables work make a manual step by step operation guide useless, and I make the assumption that user will generate iptables rules automatically, obvisouly script can dump iptables commands allowing anyone to double check what it going one.

Fridu-in-Xen security model is designed to be very simple to administrate. Firewall iptables are generated automatically through a small parser script and the administrator only have 3 rules to handle. This describe how to implemented security before you reach a given VM. Obviously each virtual machine may later have its own set of firewall rules, but this is out of scope of this guide. You should look Fridu-in-Xen security model as the equivalence of what a network/infrastructure team is providing inside a traditional Telco.

Note: Firewall has been extended to support other virtualization environment like OpenVZ or VirtualBox and has now its own page (here)

 

 
Comments (1)
'Next >' link
1 Wednesday, 10 June 2009 03:11
Daniel
Hi,
Just wanted to point out that the two sets of 'Prev - Next' links at the footer of the page are slightly confusing. Maybe the bottom ones should be called 'Older/Newer Article'
BTW, this is a great resource. I will try to understand it and apply it in a similar scenario.
=========> Fulup respond ==============
I agree that having two next/prev link on the same page is confusing :( I kept Joomla default default config, which was not a good idea.
Conclusion: I removed the article/article navigation and kept only the on to browse current article.
Thank you for the TIP.

Add your comment

Your name:
Your email:
Subject:
Comment: