Adding the output of `ip link` and `ip route list` outside and inside the sandbox.
$ ip link 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000 link/ether 74:d4:35:1e:1a:c3 brd ff:ff:ff:ff:ff:ff $ ip route list default via 192.168.1.1 dev eth0 192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.233 $ firejail --noprofile --net=eth0 Parent pid 30984, child pid 30985 Interface MAC IP Mask Status lo 127.0.0.1 255.0.0.0 UP eth0-30984 f2:9b:1d:21:6f:b9 192.168.1.69 255.255.255.0 UP Default gateway 192.168.1.1 Child process initialized $ ip link 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 2: eth0-30984: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default qlen 1000 link/ether f2:9b:1d:21:6f:b9 brd ff:ff:ff:ff:ff:ff $ ip route list default via 192.168.1.1 dev eth0-30984 192.168.1.0/24 dev eth0-30984 proto kernel scope link src 192.168.1.69