<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Using BunkerWeb and SysWarden with Xen Orchestra and/or XO Proxy]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-group plugin-mentions-a" href="/forum/groups/team-xo-backend" aria-label="Profile: Team-XO-Backend">@<bdi>Team-XO-Backend</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> Hi,</p>
<p dir="auto">Currently thought of somewhere else that Xen Orchestra and/or XO Proxy can be improved. Given that Vates uses open source software where it can, I’ve been wondering the following:</p>
<ul>
<li>Why is there only reverse proxy settings documented for connecting Xen Orchestra and/or XO Proxy to the internet?</li>
<li>Couldn’t there also be software like a Web Application Firewall also used, or providing the internet interface access?</li>
<li>There’s both open source and closed source software and services available for this! Why not document the open source instances of this, at least for the start?</li>
</ul>
<p dir="auto">I’ve opened an GitHub Issue on this topic: <a href="https://github.com/vatesfr/xen-orchestra/issues/10444" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/vatesfr/xen-orchestra/issues/10444</a></p>
<p dir="auto">The recommendation will still be to not expose it to the Internet, but there maybe situations where it’s unavoidable or the only option. Updating (patching) Vates VMS as soon as possible would still be essential. The purpose of this software combination is to provide additional defence-in-depth before, during, and after patch deployment.</p>
<p dir="auto">What does everyone think of the idea, of new additional documentation covering this?</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/danp" aria-label="Profile: danp">@<bdi>danp</bdi></a> What would it take for as feedback for this to become, part of your support packages? As this will help, protect instances of Xen Orchestra and/or XO Proxy where avoiding Internet exposure, is unavoidable due to specific requirements and/or needs. I noticed these software and thought hey, this may fill a need that currently is underserved.</p>
<p dir="auto">This could potentially create collaboration opportunities between the projects if the solution proves valuable to Xen Orchestra and/or XO Proxy users.</p>
]]></description><link>https://xcp-ng.org/forum/topic/12488/using-bunkerweb-and-syswarden-with-xen-orchestra-and-or-xo-proxy</link><generator>RSS for Node</generator><lastBuildDate>Wed, 23 Sep 2026 14:22:18 GMT</lastBuildDate><atom:link href="https://xcp-ng.org/forum/topic/12488.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 23 Sep 2026 12:26:50 GMT</pubDate><ttl>60</ttl></channel></rss>