[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xense-devel] Secure Network Communications Between Xen VMs



Hi all,

I have two questions about the secure network communications between Xen VMs (i.e. domains) residing on different physical machines. 1) By way of example, if domU1 on machine M1 is communicating with two other domains, domU2 and domU3 on machine M2, how does the hypervisor/ACM on M1 differentiate between inbound/outbound traffic destined only for domU2 or domU3 and ensure that traffic is routed to the proper domain? 2) Is all of the traffic between various domains encrypted to prevent eavesdropping via network sniffing? I've read the paper, "DeuTeRium -- A System for Distributed Mandatory Access Control" but it's not clear to me from the actual implementation examples and documentation how you set up the IPSEC labeled tunneling mechanism and ensure validation of all traffic passing between the various domains.

Thanks,
Mike Schumann


_______________________________________________
Xense-devel mailing list
Xense-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xense-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.