FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Virtualization and firewalling?

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.cybertrust.com>
Subject: Re: [fw-wiz] Virtualization and firewalling?
From: Carric Dooley <carric@com2usa.com>
Date: Thu, 22 Mar 2007 12:09:22 -0500 (EST)
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <Pine.LNX.4.44.0703181426130.12867-100000@bat.clueby4.org>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
The only firewall virtualization I have seen is VSX, Crossbeam, and 
Shasta, but I don't know of any host-based solution per-se.  Is there some 
issue I'm missing (since I have not tried this myself) installing some 
centrally managed host-based FW/IPS on VM's?

On Sun, 18 Mar 2007, Paul D. Robertson wrote:

> On Sun, 18 Mar 2007, Robby Cauwerts wrote:
> 
> > > Now we're starting to see a big push for hardware virtualization, is
> > > anyone seeing a move to per-virtual-system firewalling on the hosting OS?
> > 
> > 
> > This is already available for years on the firewall market.
> > Check Point VSX (If money is no problem), Cisco ASA with their security
> > contexts, ....
> 
> Aren't these just a way of packaging rules on an appliance rather than 
> providing access control on a hosting OS?  While there's likely to be some 
> immediate benefit from appliances if you do moving of guests around the 
> same physical subnet, that's not going to scale to moving to alternate 
> locations very well, where you're going to need the hosting OS anyway.
> 
> Also, as we get to things like the newer Linux KVM, won't we start to see 
> the ability to compratment based on the hosting system being part of the 
> TCB?
> 
> Paul
> -----------------------------------------------------------------------------
> Paul D. Robertson      "My statements in this message are personal opinions
> paul@compuwar.net       which may have no basis whatsoever in fact."
>              http://www.fluiditgroup.com/blog/pdr/
> 
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> 
> 

-- 
Carric Dooley
COM2:Interactive Media USA
http://www.com2usa.com


-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>