Static Jail ID's (JID's) for use with IPFW?

2013-08-07 Thread Karl Pielorz
Hi, I have a number of jailed systems running - and I've been setting up ipfw rules for them. This is on FBSD 9.1. 'ipfw' lets you match on traffic to/from a Jail ID (JID) - however every time jails get started / stopped their JID changes [thus breaking the firewall rules]. I can't see

Re: Static Jail ID's (JID's) for use with IPFW?

2013-08-07 Thread Arthur Chance
On 07/08/2013 09:28, Karl Pielorz wrote: I have a number of jailed systems running - and I've been setting up ipfw rules for them. This is on FBSD 9.1. 'ipfw' lets you match on traffic to/from a Jail ID (JID) - however every time jails get started / stopped their JID changes [thus breaking the

Re: Static Jail ID's (JID's) for use with IPFW?

2013-08-07 Thread Fbsd8
Karl Pielorz wrote: Hi, I have a number of jailed systems running - and I've been setting up ipfw rules for them. This is on FBSD 9.1. 'ipfw' lets you match on traffic to/from a Jail ID (JID) - however every time jails get started / stopped their JID changes [thus breaking the firewall

Re: Static Jail ID's (JID's) for use with IPFW?

2013-08-07 Thread Karl Pielorz
--On 07 August 2013 12:23 +0100 Arthur Chance free...@qeng-ho.org wrote: I don't think the old /etc/rc.conf way of handling jails lets you do it, but the latest version of jail(8) introduced /etc/jail.conf and you should be able to add jid = N; parameters in there. Thanks - I'll check that