I have (5) NICs in a machine (eth0 to eth4). I want to run a firewall in a DomU (not in Dom0). We want to bond eth0/eth1/eth2 into bond0 and eth3/eth4 into bond1. Bond0 - LAN Bond1 - Internet What is the path of least resistance? Should we do the bonding in Dom0, and pass a pair of bridged VIFs to the DomU firewall? Or should we pass eth3 and eth4 to the DomU firewall domain as PCI front/back-end devices? There will be other DomUs running that will only be talking to the Bond0 bridge and the DomU firewall will be forwarding ports to those DomUs. _______________________________________________ Xen-users mailing list Xen-users@lists.xensource.com http://lists.xensource.com/xen-users