RE: vnet jail and ipfw/nat on host - keep-state problem?

2014-07-11 Thread Peter Ross
On Thu, 10 Jul 2014, Peter Toth wrote: Hi Peter, Try to make these changes: net.inet.ip.forwarding=1       # Enable IP forwarding between interfaces net.link.bridge.pfil_onlyip=0  # Only pass IP packets when pfil is enabled net.link.bridge.pfil_bridge=0  # Packet filter on the bridge interface

Jail vnet features

2014-07-11 Thread Marcin Michta
Hello, I want to ask what are advantages and disadvantages using VNET? I know that it allows each jail to have a private networking stack, but what else? Regards Marthin ___ freebsd-jail@freebsd.org mailing list

Re: vnet jail and ipfw/nat on host - keep-state problem?

2014-07-11 Thread Fbsd8
Peter Toth wrote: Have not used natd with IPFW much as always preferred PF to do everything on the host. I have only a wild guess - the me keyword in IPFW is substituted only to the host's IPs known to itself. The host's IPFW firewall most likely doesn't know anything about IPs assigned to vnet

Re: Jail vnet features

2014-07-11 Thread Fbsd8
Marcin Michta wrote: Hello, I want to ask what are advantages and disadvantages using VNET? I know that it allows each jail to have a private networking stack, but what else? Regards Marthin Its experimental, it has many bugs posted in PR system, loses memory every time a vnet

Re[2]: Jail vnet features

2014-07-11 Thread wishmaster
--- Original message --- From: Fbsd8 fb...@a1poweruser.com Date: 11 July 2014, 16:49:08 Marcin Michta wrote: Hello, I want to ask what are advantages and disadvantages using VNET? I know that it allows each jail to have a private networking stack, but what else?

[Bug 142972] [jail] [patch] Support JAILv2 and vnet in rc.d/jail

2014-07-11 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=142972 jo...@a1poweruser.com changed: What|Removed |Added CC||jo...@a1poweruser.com ---

Re: vnet jail and ipfw/nat on host - keep-state problem?

2014-07-11 Thread Peter Toth
Dear Joe Barbish (alias fb...@a1poweruser.com), When you going to stop trolling the FreeBSD mailing list and spread disinformation? For anyone interested please check this mail thread on who fbsd8 really is: http://lists.freebsd.org/pipermail/freebsd-jail//2013-March/002147.html Very telling