Re: Can we run a qemu instance as a dedicated home network firewall?



On 14:04 Sun 30 Mar , Douglas A. Tutty wrote:
On Sun, Mar 30, 2008 at 11:20:26AM -0400, Mitchell Laks wrote:
Can we use a virtual qemu linux machine as a firewall for
a real home network?

Well, on normal i386 hardware (unlike e.g. Zseries with LPARs),
virtualization doesn't gain you any security really. Think of it this
way: the only way an attacker can break the firewall if its running
natively on the one box, is a bug in the kernel. With virtualizaiton,
you're relying on both no bugs in the kernel and no bugs in the quemu.

A very good point. Thank you.


This comes up a lot on misc@xxxxxxxxxxxx Their analysis shoes that it
decreases security to use software virtualization.

Those old 486s didn't themselves take much power. If the problem is
noise, you could replace the drives with industrial CF cards for the
firewall.

Also a great idea. I see cf-hard drive adapters and drives are very cheap.
Thank you very much,

Mitchell


doug.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Can we run a qemu instance as a dedicated home network firewall?
    ... virtualization doesn't gain you any security really. ... you're relying on both no bugs in the kernel and no bugs in the quemu. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Virtual PC using WinXP for Win98SE - help
    ... I can't even use VPC to run a DOS VM, because *within VPC*, and booting up ... BUT when booting up in DOS on the floppy *within VPC*, ... Drives in the VM have nothing to do with drives on the physical machine. ... of the biggest benefits of virtualization. ...
    (microsoft.public.windowsxp.general)
  • Re: Freeze SO Linux, its possible?
    ... your probably going to be getting a lot of nasty messages - cross posting to multiple lists like this, and sending a non-security related message to a security list is deeply frowned upon. ... you might want to look at some sort of virtualization answer like VMware or Xen. ... To UNSUBSCRIBE, email to debian-security-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: OT: Computers
    ... perhaps one of the shifts will be having PCs with locked hard drives ... Even further are programs like VMWare ACE which basically streams a ... I've also worked with several large Citrix environments where the ... built in virtualization. ...
    (rec.gambling.poker)
  • Re: HP X510 data vault vs MediaSmart EX487
    ... I installed mine on a Win2003 server running Virtual Server 2005. ... No problems and the test bare metal restore of my SBS2003 server worked fine from the backup. ... It needs lots of disk space, and physical disk expansion, or external drives, often work via USB, so that is a problem with some virtualization software, I believe. ...
    (microsoft.public.windows.server.sbs)