[Users] openvz and SuSE
Daniel Bauer
mlist at dsb-gmbh.de
Fri Feb 3 08:37:13 EST 2006
From: "Mishin Dmitry" <dim at sw.ru>
> On Friday 03 February 2006 15:38, Daniel Bauer wrote:
>> is it possible to take another way to work on Ethernet level, because
>> I
>> don't want a official IP for the host.
>> 1. security
>> 2. no need for
>> 3. one official IP less for each block
> If you have only one or two VPSs, you can use real devices dedicated
> to each
> VPS, but this is not your case. For now, we don't work on Ethernet
> level and
> you are required to have one more real IP for the block.
>
> I suppose, that from security point of view it is a not big deal,
> while you
> can use netfilter to protect it and additionally all VPSs, because
> their
> traffic goes through HN route tables.
>
> If it is still the problem, you can check Virtuozzo's Name Based
> Hosting
> feature - it allows to use one real IP for multiple VPSs (pop, smtp,
> http,
> ftp)
Hello Dmitry,
thanks for your explaination.
If I understand you right, you do the firewalling on the host, not in
the VPS. I think it will work and I could afford one more IP for the
host, but my opinion was to have less as possible on my host and let the
VPS do the work ;)
Thanks again
Daniel
More information about the Users
mailing list