[Users] openvz and SuSE

Daniel Bauer mlist at dsb-gmbh.de
Fri Feb 3 08:37:13 EST 2006


From: "Mishin Dmitry" <dim at sw.ru>
> On Friday 03 February 2006 15:38, Daniel Bauer wrote:
>> is it possible to take another way to work on Ethernet level, because 
>> I
>> don't want a official IP for the host.
>> 1. security
>> 2. no need for
>> 3. one official IP less for each block
> If you have only one or two VPSs, you can use real devices dedicated 
> to each
> VPS, but this is not your case. For now, we don't work on Ethernet 
> level  and
> you are required to have one more real IP for the block.
>
> I suppose, that from security point of view it is a not big deal, 
> while you
> can use netfilter to protect it and additionally all VPSs, because 
> their
> traffic goes through HN route tables.
>
> If it is still the problem, you can check Virtuozzo's Name Based 
> Hosting
> feature - it allows to use one real IP for multiple VPSs (pop, smtp, 
> http,
> ftp)

Hello Dmitry,

thanks for your explaination.

If I understand you right, you do the firewalling on the host, not in 
the VPS. I think it will work and I could afford one more IP for the 
host, but my opinion was to have less as possible on my host and let the 
VPS do the work ;)

Thanks again
Daniel



More information about the Users mailing list