Re: [ovirt-users] Ovirt Engine WAN security

2014-12-19 Thread Martijn Grendelman
Donny Davis schreef op 18-12-2014 om 23:25:
> I would like to inquire if anyone is using the ovirt engine to control
> remote datacenters, and if so.. How are you securing it. I realize you
> cannot devulge trade secrets or your actual setup.. Just general info,
> like we are using vpn, or SSH..

We use a 'management VLAN', only reachable through VPN.

Best regards,
Martijn.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [ovirt-users] Ovirt Engine WAN security

2014-12-19 Thread Alon Bar-Lev

Hello,

Ovirt engine->vdsm communication cannot be exposed to the public Internet.
vdsm was not designed to be opened to the public.
You should use VPN between the engine and hosts, and add firewall to allow 
http/https access to engine.
Using novnc and websocket proxy will enable you to reroute the display 
communication via the engine as well.

Regards,
Alon

- Original Message -
> From: "Donny Davis" 
> To: users@ovirt.org
> Sent: Friday, December 19, 2014 12:25:45 AM
> Subject: [ovirt-users] Ovirt Engine WAN security
> 
> 
> 
> I would like to inquire if anyone is using the ovirt engine to control remote
> datacenters, and if so.. How are you securing it. I realize you cannot
> devulge trade secrets or your actual setup.. Just general info, like we are
> using vpn, or SSH..
> 
> 
> 
> Thanks for any info anybody can provide.
> 
> Donny D
> 
> ___
> Users mailing list
> Users@ovirt.org
> http://lists.ovirt.org/mailman/listinfo/users
> 
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[ovirt-users] Ovirt Engine WAN security

2014-12-18 Thread Donny Davis
I would like to inquire if anyone is using the ovirt engine to control
remote datacenters, and if so.. How are you securing it. I realize you
cannot devulge trade secrets or your actual setup.. Just general info, like
we are using vpn, or SSH.. 

 

Thanks for any info anybody can provide.

Donny D

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users