• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Virtualized computing under Fedora 10 with a dual core processor

EvilGenesys

[H]ard|Gawd
Joined
Jan 31, 2002
Messages
1,319
I recently ditched Windows in favor of Fedora 10 - mostly because I am tired of the Windows bloat factor, but also because I want to run something more secure.

With that being said, it seems to me that when I would run VirtualBox under WinXP, I could run multiple virtual machines (Server 2K3 and 7 beta) without occupying all of the host system resources.

Fast forward to now, and it seems like running one virtual machine ties up one of the CPU cores while host system ops occupy 20% of the other - and when I try to run two VMs, the system just crawls.

So, the questions I have are this:

Does Linux just not like to virtualize Windows?
I plan on doing a new system build at some point later this year, am I going to see a significant jump in performance with new hardware (I am planning on a quad core Core i7 system)?
Does the fact that my CPU lacks hardware support for virtualization significantly imact performance?

Thanks!
 
Most Linux implementations that provide a Xen kernel, which are not licensed, are limited to one virtual machine per CPU core. Are you running a Xen kernel, or something else? It would be helpful. You told us that under Windows, you were using VirtualBox...but not what you're running VMs with under Linux.

Hardware VT support would be useful. If you intend to run non-concurrent architectures between the VMs and the host machine, it would be very helpful (as in, a 64bit host,w ith 32bit VMs, and visa versa). Since you're running a Type2 Hypervisor, you will always be limited to the performance capabilities of the underlying OS. FYI, Fedora has always been, and continues to be the "wonky, beta version of RedHat." I wouldn't run Redora as my main OS, as a rule of thumb. I'd run Redhat, and virtualize Fedora.

Without trying to start a flame war, Linux isn't any more secure than any other OS. It's all in how you DO or DON'T lock it down. Anything can be 100% secure...don't connect it to a network, never tel anyone where it exists, put it in a locked room that hidden from view, and never power it on. Otherwise, you're fooling yourself.
 
Most Linux implementations that provide a Xen kernel, which are not licensed, are limited to one virtual machine per CPU core. Are you running a Xen kernel, or something else? It would be helpful. You told us that under Windows, you were using VirtualBox...but not what you're running VMs with under Linux.

Hardware VT support would be useful. If you intend to run non-concurrent architectures between the VMs and the host machine, it would be very helpful (as in, a 64bit host,w ith 32bit VMs, and visa versa). Since you're running a Type2 Hypervisor, you will always be limited to the performance capabilities of the underlying OS. FYI, Fedora has always been, and continues to be the "wonky, beta version of RedHat." I wouldn't run Redora as my main OS, as a rule of thumb. I'd run Redhat, and virtualize Fedora.

Without trying to start a flame war, Linux isn't any more secure than any other OS. It's all in how you DO or DON'T lock it down. Anything can be 100% secure...don't connect it to a network, never tel anyone where it exists, put it in a locked room that hidden from view, and never power it on. Otherwise, you're fooling yourself.

I have no idea if I am running a Xen Kernel or not... how do I tell?

I continue to run VirtualBox under Linux... I am most familiar with VirtualBox and VirtualPC... but I dislike VirtualPC, and it also does not run natively under Linux.

I am runing an x64 implementation of Fedora, and the OSes I virtualize are the 32 bit versions. How exactly does this imact my performance? I realize that Red Hat is the *more* stable OS when comparing Fedora to it, but I have never had a problem - Fedora, in any implementation that I have used has never failed or given me any problems. This might be because I am not the type of user to try and modify many of the core aspects of the OS, or it just might be that I am very lucky. Either way, I cannot tell much of a difference in user experience between Fedora and RH.

I understand where you're coming from when you say Linux isn't any more secure than any more OS, but you take a very text book approach to your argument. From a usability standpoint, what is the purpose of having a computer in this day and age without connecting it to a network, acknowledging its existence, powering it on, and/or otherwise using it to its fullest capability? The fact of the matter is, Windows is by far the more exploitable and therefore less secure OS. Windows also has the largest install base between the two, and as such, most hackers/crackers/script kiddies wast their time trying to exploit Windows based computers. This inherently gives Linux a more secure operating environment.
 
Gotcha. VirtualBox under Linux is going to be different than a Xen kernel. Some Linux distributions (Red Hat Advanced Plaform comes to mind) have the option (during the installation process) to run a Xen kernel. When you do this, the Xen Virtual Machine Manager is installed, and the underlying Red Hat OS is taking advantage of the Xen kernel, which is specifically designed to run VMs. When you do this, it's a Type 1 hypervisor. VirtualBox is a Type 2 Hypervisor, and is only tied to the underlying OS in that it requires one in order to operate.

Not having any VirtualBox experience myself, I will have to defer to someone else's experiences and expertise on this.

Regarding security, like I said, I was not trying to start a flame war. My approach is very textbook, true. Your response, however, hits the nail on the head. Windows (being the most widely used operating system in existence) is a continual target for all sorts of attacks. It is this prevalence that causes the issue, not the ability to secure (or not secure) the OS better than others. If you intend to use a modern computer as a modern computer (and connect it to any type of network) then any OS is potentially at risk...even your virtual ones. Nothing changes.
 
sabregen,

When I installed Fedora, I installed an optional package called Virtual Machine Manager... does this have any relation to Xen? If so, what is the relation and how would I go about taking advantage of it? I'll definitely have to do some more research into virtualized computing - are there any resources that you would recommend?

My security strategy is not really one of risk mitigation, it is risk avoidance :) I could try and secure a Windows platform indefinitely, but there is always something new because of its ubiquity. And maintaining a high level of security has a high impact on performance - one which I would have to make when using an OS which a large segment of the population pays little attention to.
 
Oh, and go with the 9-cell battery for your Aspire One. It adds a little bit of weight and makes it a little bulkier on the backend, but it works wonderfully. Personally, I think the 6-cell will just be a waste of your time and money - all of those mods will present quite the battery drain and I imagine you'll be far happier with the extended life that the 9-cell would give you.

Just my .02
 
The virtual machine manager in Linux distros is a package that you install dutring the OS installation. However, not being a Linux guru, and having only started to poke around in our Xen implementation at work (I do the VMWare side), I don't know if there's a direct correlation between the VMM installed package and the underlying Xen kernel. I am under the impression that they can be mutually exclusive. I can tell you that you would definately know if you were running a Xen kernel. The packages, drivers, etc that you install on the host OS have to be compatible with a Xen kernel, and you can't (as a general rule) use regular 2.6 packages for a Xen kernel. Specifically, with regard to MPIO/RDAC/PCI device drivers. I think it has to do with any system component that has potentially heavy IO requirements. Also, what comes to mind is that virtualization today virtualizes the CPU, RAM, disk, and IO. Perhaps, because the Xen kernel (and other Type 1 Hypervisors) does this at the lowest level possible, those particular drivers (because they have the potential to be scheduled to guest VMs) have to support the Xen kernel, which is performing this function.

As far as getting more information on VMM, Xen kernels, etc. Unfortunately, I can't be of much use there. I am just getting started on Xen, myself. All of my background so far is centered around VMWare solutions. I have some knowledge in the supporting technologies for all virtualization solutions, but I am still learning, myself.

And on the 9cell battery...I hear ya. You're probably right, as well. The 9cell makes this otherwise thin and light netbook a bulky little bastard. However, my current 3cell does not run long enough for my tastes.
 
Oh, and security at any level always impacts performance. This is the very reason that we have security appliances. The impact to run all of the security required on each machine on a network (for acceptable operational levels) would come at a cost of a certain percentage of each machine's capabilities, which would then aggregate across all the machines in the environment. Having special purpose security appliances helps mitigate this issue. Unfortunately, they're usually expensive.

...Oh, and SmartNet is like AppleCare. If you use it once, it's "worth it." But saying it's worth it really means that you're okay with getting raped on support for a proprietary platform that cost twice as much as the leading competitor...just so that you can run their nifty software, and rub elbows with all of your other smug little chums....who also paid twice as much for a closed platform, and won't admit they're idiots.

/rant
 
Back
Top