Re: ipfw + bridge + epair + tags for vnet jails after upgrade to 13.1

2022-12-21 Thread Kristof Provost
the outside >> world where my hoster looks unkindly on mac-addresses not belonging to >> the nic of my server. So I have vnet jails behind a common ifbridge. >> All jails have their default routes point to the bridge-interface of >> the host. The host works as a rou

Re: ipfw + bridge + epair + tags for vnet jails after upgrade to 13.1

2022-12-21 Thread Andrey V. Elsukov
of my server.  So I have vnet jails behind a common ifbridge. All jails have their default routes point to the bridge-interface of the host.  The host works as a router. Tags stopped working across vnet and bridge --- On a long running host that is still

ipfw + bridge + epair + tags for vnet jails after upgrade to 13.1

2022-12-20 Thread Markus Graf
where my hoster looks unkindly on mac-addresses not belonging to the nic of my server. So I have vnet jails behind a common ifbridge. All jails have their default routes point to the bridge-interface of the host. The host works as a router. Tags stopped working across vnet and bridge

[Bug 178482] [ipfw] logging problem from vnet jail

2020-07-25 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=178482 Mark Linimon changed: What|Removed |Added Assignee|b...@freebsd.org|i...@freebsd.org -- You are

Re: Dummynet, pipes and VNET jails

2020-06-05 Thread Peter
a problem with ipfw/dummynet, pipes and VNET jails using FreeBSD 12.0 ! release. Packets are lost in the pipe when any impairments are configured. ! ! I set up several VNET jails and connected them via epairs, in order to ! do tests with different network and routing configurations. On some jails

Dynamic Ipfw and vnet deletion

2018-05-09 Thread Dheeraj Kandula
Hi All, When a vnet is deleted, I see that the function vnet_ipfw_uninit is invoked which invokes uma_zdestroy to destroy the zone. When dynamic firewall rules are added, the function add_dyn_rule allocates memory from the ip fw zone using the function uma_zalloc. However the expired

Re: kern/178482: [ipfw] logging problem from vnet jail

2013-05-22 Thread Ian Smith
The following reply was made to PR kern/178482; it has been noted by GNATS. From: Ian Smith smi...@nimnet.asn.au To: bug-follo...@freebsd.org, fb...@a1poweruser.com Cc: Subject: Re: kern/178482: [ipfw] logging problem from vnet jail Date: Wed, 22 May 2013 23:44:40 +1000 9.1-RELEASE kernel

Re: kern/178482: [ipfw] logging problem from vnet jail

2013-05-19 Thread linimon
Old Synopsis: ipfw logging problem from vnet jail New Synopsis: [ipfw] logging problem from vnet jail Responsible-Changed-From-To: freebsd-bugs-freebsd-ipfw Responsible-Changed-By: linimon Responsible-Changed-When: Mon May 20 03:26:47 UTC 2013 Responsible-Changed-Why: Over to maintainer(s

Re: VNET

2012-06-20 Thread Alexander V. Chernikov
On 19.06.2012 12:56, Sami Halabi wrote: Hi, I want to ask aout VNET jails, i read somehwre that I'm able to run IPFW, but not PF firewall in a cnet jail. is that correct? i want a vnet jail basicly for nat, so natd with ipfw + ipdivert is my 1) You can do nat without vnet. 2) ipfw nat

Re: VNET

2012-06-20 Thread Sami Halabi
Thank you. I want to use vnet jail for a specific subnet that I need to seperate from the system. so basicly i create a vlan + a bridged interface to the public. these two (vlan+bridged interface- epair0a) will in in the vnet jail, so I can do NAT only for that vlan going out. This is the idea

dummynet and vnet kernel panic

2010-04-07 Thread Anders Hagman
Hi When using dummynet inside a vnet node with a simple pipe the kernel panic on the first packet. I use 8.0-STABLE cvsuped at 7 Apr 15:28 The ipfw code with dummynet is largely changed and the patch in the url below will not work. http://www.freebsd.org/cgi/query-pr.cgi?pr=143621

Re: dummynet and vnet kernel panic

2010-04-07 Thread Julian Elischer
On 4/7/10 1:38 PM, Luigi Rizzo wrote: On Wed, Apr 07, 2010 at 09:58:38PM +0200, Anders Hagman wrote: Hi When using dummynet inside a vnet node with a simple pipe the kernel panic on the first packet. I use 8.0-STABLE cvsuped at 7 Apr 15:28 The ipfw code with dummynet is largely changed

Re: kern/143621: [ipfw] [dummynet] [patch] dummynet and vnet use results in panic

2010-02-06 Thread linimon
Old Synopsis: [patch] dummynet and vnet use results in panic New Synopsis: [ipfw] [dummynet] [patch] dummynet and vnet use results in panic Responsible-Changed-From-To: freebsd-bugs-freebsd-ipfw Responsible-Changed-By: linimon Responsible-Changed-When: Sun Feb 7 05:33:05 UTC 2010 Responsible