I don't think it's a good idea either, but if they want to, they want to.
Personally I don't even think it's a good idea to run a firewall virtualized for real use (for home use, whatever).
... but the logic of the above escapes me.
We plan to add support for running ASG as a guest under Citrix XEN Server.
All that said, I'm really looking forward to getting my copy of v8 Beta installed next week on a new ESXi image for testing. [:D]
So, the definitive answer is: XEN paravirtualization is not possible under the kernel shipped currently (it was suggested in another thread that it might work, though not being officially supported).
In /boot/config-2.6.32.10-10-smp64
is to be found:
# CONFIG_PARAVIRT_GUEST is not set
I know about all of that ! [:)]
personally was speaking about building a custom kernel with xen patches...
will investigate very soon...
Maybe that's because you look at it from a more technical perspective.