Dag Richards wrote:

> Jason Dixon wrote:
> > On Thu, May 21, 2009 at 08:05:52AM -0700, Obiozor Okeke wrote:
> > > Well I should have mentioned that the ESXi is also running a Windows 
> > > server VM \
> > > for a custom app that requires it.  So the idea was to have one box 
> > > running ESXi \
> > > and reduce hardware costs.
> > 
> > 
> > BWAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHA!!!!
> > 
> > 
> > *whew*
> > 
> > Thanks, I needed that.
> 
> 
> Er yes, you will not be able to get there from here.
> 
> Re-think.
> 
> 
> Don't run vmware on your firewall.
> 
> If you virtualize your entire DC in to a single box, still don't run 
> your firewall as a vm.
 
 
Run a firewall on *hardware* that is not doing anything else.  The firewall is 
practically by definition the thing that is NOT protected by something else; 
have no additional holes in it or in what it relies on.  Like VMWare, or a 
Windows application server.

--
Ed Ahlsen-Girard
Ft. Walton Beach FL

Reply via email to