Re: [zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-12 Thread Tommy McNeely
Well, I forgot to mention that we were using S10u6, but the idea I had was to apply the filter rules in the global zone. As far as I can tell, crossbow is not integrated with NV or OS either :) It looks like we are going to need to somehow wrapper it, or put the entire ipf.conf for all zones

Re: [zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-12 Thread Tommy McNeely
I have about 50-60 zones spread across 3 security contexts ;) ~tommy On Nov 12, 2008, at 6:38 PM, Ha Bailey wrote: Have you considered Trusted Extensions? As long as you do not need multiple zones of the same security context on the same physical server, it might work out for you. (in

Re: [zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-09 Thread Jeff Victor
On Fri, Nov 7, 2008 at 12:13 PM, Tommy McNeely [EMAIL PROTECTED] wrote: Hello Zones experts, We are attempting to create a new data center architecture that favors virtualization with zones. Previously, if we wanted to have zones from different security contexts (front-end, back-end,

[zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-07 Thread Tommy McNeely
Hello Zones experts, We are attempting to create a new data center architecture that favors virtualization with zones. Previously, if we wanted to have zones from different security contexts (front-end, back-end, internet, etc), they had to be in different physical machines (or LDOMS). Now