xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
From: Kashyap Thimmaraju <kashyap.thimmaraju@sec.t-labs.tu-berlin.de>
To: xen-devel@lists.xen.org
Cc: George Dunlap <george.dunlap@citrix.com>
Subject: Deployment usage and performance of a network domain
Date: Thu, 8 Jun 2017 14:32:53 +0200	[thread overview]
Message-ID: <593943F5.3030108@sec.t-labs.tu-berlin.de> (raw)

[-- Attachment #1: Type: text/plain, Size: 1503 bytes --]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi,

I'm Kashyap Thimmaraju, a second year PhD student at TU Berlin in
Germany. This is my first post here, and I'm a Xen newbie.

I saw George Dunlap's presentation "Securing Your Xen-Based Cloud" at
the LinuxCon on youtube recently as I am interested in using the
driver domain for networking.

In the presentation he proposed placing the network driver  and
forwarding functionality (bridge, iptables, etc.) into a (network)
driver domain. This is indeed good for security.

However, I am curious if people are really adopting such an approach.
Are there cloud providers or PV vendors deploying such an
architecture? If so, is there any impact on the networking performance
of say VM-VM or VM-Internet traffic?

Thanks,
- -- 
Kashyap Thimmaraju <kashyap.thimmaraju@sec.t-labs.tu-berlin.de>
Security in Telecommunications <sec.t-labs.tu-berlin.de>
TU Berlin / Telekom Innovation Laboratories
Ernst-Reuter-Platz 7, Sekr TEL 16 / D - 10587 Berlin, Germany
Phone: +49 30 8353 58351
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJZOUP1AAoJEKEOZw+VIHXN8usH/RHhBw9xXSyp8zrxBcCOH+/G
o3maD+LV5fHBxKlAsSPOAV88LdZI9SKEUvChqj/pLESTEYzvGdc/wwShBepczMjm
XIiCb+B5WkXUOqNEwjERZAzhptnHH6asNbPTsPQm7u634LCncSmNrWHSEpZpMeCQ
+eAa52ywKO/ArXODUzKqhuFRVrdFeKASbGb3rL93cogOC1TDiSrdzX3mHUvJe9qJ
iRlKUaJi6IeNbxa29W1hbED/NJfg7lWFSBuB55glX08ORxsEk3MATnnHXeYw9VMk
Yxpg6zxsaqnYO60HCksSjeuj7KLyfEiWIELnRkBCdptpaPKfJnTilNdt1aD5ALw=
=jPVg
-----END PGP SIGNATURE-----

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #2: kashyap_thimmaraju.vcf --]
[-- Type: text/x-vcard; name="kashyap_thimmaraju.vcf", Size: 4 bytes --]

null

[-- Attachment #3: Type: text/plain, Size: 127 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
https://lists.xen.org/xen-devel

             reply	other threads:[~2017-06-08 12:32 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-06-08 12:32 Kashyap Thimmaraju [this message]
2017-06-08 17:07 ` Deployment usage and performance of a network domain Dario Faggioli
2017-06-12  8:18   ` Kashyap Thimmaraju
2017-06-14  8:10     ` Dario Faggioli
2017-06-14  8:13       ` Kashyap Thimmaraju

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=593943F5.3030108@sec.t-labs.tu-berlin.de \
    --to=kashyap.thimmaraju@sec.t-labs.tu-berlin.de \
    --cc=george.dunlap@citrix.com \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).