Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Peter Memishian
> You mean if zone1 and zone2 were plumbed on e1000g1:1, and e1000g1:2, > traffic will never be observable no matter what. I can live with > this. All IP packets can be observed as of Nevada build 103; see http://blogs.sun.com/seb/ for some examples with zones. -- meem _

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Christine Tran
> You can add multiple physicals to a shared stack zone, they are > just added as logicals. You need the underlying interface plumbed > in the global zone though. An exclusive stack doesn't know anything > about other zones' network configuration. OK, I'm beginning to see. Like this, you mean? g

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Jon Anderson
> > But how could that be ... shared-stack zone with IP address on > different interface? This thing cannot exist? You can add multiple physicals to a shared stack zone, they are just added as logicals. You need the underlying interface plumbed in the global zone though. An exclusive stack do

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Christine Tran
>> Unless ip_restrict_interzone_loopback is 0 (the default is 1 on OS). >> You can have zones of type exclusive-ip plumbed on different >> interfaces but not cabled up if this parameter is set to 0. > > Where is this documented? This is what started the whole kerfuffle for me, https://www.openso

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Jon Anderson
I may be wrong on this as I haven't looked for quite a long while now (and things change rapidly) but Exclusive stack zones means you get a separate IP stack and, therefore, a separate routing table. This means that we don't know anything about interfaces which are 'local' to other zones on th

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Christine Tran
On Fri, Jan 23, 2009 at 4:27 AM, Jon Anderson wrote: > Hi, > > Do you have more details on your zone configuration? If you are > using exclusive stack zones then this is expected. > Hmm, I thought the exact opposite. zones of type exclusive-ip type, plumbed on different interfaces, will drive th

Re: [zones-discuss] ip_restrict_interzone_loopback again

2009-01-23 Thread Jon Anderson
Hi, Do you have more details on your zone configuration? If you are using exclusive stack zones then this is expected. Rgds, Jon Christine Tran wrote: > Hi, > > Has anyone *actually* observe that you can communicate between zones > with the cable removed when /dev/ip ip_restrict_interzone_loo

[zones-discuss] ip_restrict_interzone_loopback again

2009-01-22 Thread Christine Tran
Hi, Has anyone *actually* observe that you can communicate between zones with the cable removed when /dev/ip ip_restrict_interzone_loopback is set to 0? Here's my setup, s10u5. global: 192.168.1.60/24 e1000g0, cabled zone1: 192.168.1.61/24 e1000g1, cabled zone2: 192.168.1.62/24 e1000g2, not cabl