From owner-freebsd-questions@FreeBSD.ORG Sun May 28 08:17:24 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 56D6F16BEBB for ; Sun, 28 May 2006 08:02:13 +0000 (UTC) (envelope-from m.seaman@infracaninophile.co.uk) Received: from smtp.infracaninophile.co.uk (happy-idiot-talk.infracaninophile.co.uk [81.187.76.162]) by mx1.FreeBSD.org (Postfix) with ESMTP id A13BA43D46 for ; Sun, 28 May 2006 08:02:12 +0000 (GMT) (envelope-from m.seaman@infracaninophile.co.uk) Received: from [IPv6:::1] (localhost [IPv6:::1]) by smtp.infracaninophile.co.uk (8.13.6/8.13.6) with ESMTP id k4S82474010330; Sun, 28 May 2006 09:02:05 +0100 (BST) (envelope-from m.seaman@infracaninophile.co.uk) Message-ID: <447958F7.1020104@infracaninophile.co.uk> Date: Sun, 28 May 2006 09:01:59 +0100 From: Matthew Seaman Organization: Infracaninophile User-Agent: Thunderbird 1.5.0.2 (X11/20060423) MIME-Version: 1.0 To: Yudai Yamagishi References: <001c01c681ff$38d1e080$0b0ba8c0@GATEWAY> In-Reply-To: <001c01c681ff$38d1e080$0b0ba8c0@GATEWAY> X-Enigmail-Version: 0.94.0.0 Content-Type: multipart/signed; micalg=pgp-ripemd160; protocol="application/pgp-signature"; boundary="------------enig58B1961704ED22B370E96E0F" X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.0.2 (smtp.infracaninophile.co.uk [IPv6:::1]); Sun, 28 May 2006 09:02:05 +0100 (BST) X-Virus-Scanned: ClamAV 0.88.2/1489/Sat May 27 14:47:18 2006 on happy-idiot-talk.infracaninophile.co.uk X-Virus-Status: Clean X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00,NO_RELAYS autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on happy-idiot-talk.infracaninophile.co.uk Cc: freebsd-questions@freebsd.org Subject: Re: namebased VPS using JAIL X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 28 May 2006 08:17:38 -0000 This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig58B1961704ED22B370E96E0F Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: quoted-printable Yudai Yamagishi wrote: > Hey, >=20 > I'm trying to serve several VPS for my friends. >=20 > But, IP addresses costs too much here in Japan. >=20 > So, I only have 1 WAN IP. >=20 > I've heard that Virtuozzo let's users create namebased VPS. >=20 > For example, I want to create a VPS called vps1. >=20 > I'll assign vps1.codebusterz.net as VPS's address. >=20 > Then all network traffics for vps1.codebusterz.net will go to vps1. >=20 > Same with other VPSs by the way. >=20 > Is this possible using JAIL? >=20 > Thanks >=20 > Yudai Yamagishi This would only be possible if the protocols your users used to connect to your server included the name of the server they wanted to connect to in the data packets setting up the connection. That is the case in eg. HTTP/1.1 and it sort of applies to SMTP. However, those are pretty much the exceptions rather than the rule. Most network protocols just have the IP and port number of the service they want to connect to. So long as you can arrange for each instance of a given service to run on a distinct port number, you can use the standard NAT type function= s in pf(4) or ipfw(8)+natd(8) to hide a whole private network of servers behind a single IP number. You can also use this on a single server with jail(8) by binding the jailed IPs to the loopback interface, and using NAT on the external interface to rewrite the addresses on incoming traffic. NAT is generally used in the other direction though -- to let a private network access the Internet. If you can use protocols where the name of the server is included in the data payload, you will need to set up some sort of proxy server on your firewall to direct the traffic internally. Standard firewall stuff just looks at the packet headers (layer 2 or 3) and you need extra software to= do protocol (layer 4) dependent processing. It is a toss up as to whethe= r suitable software will be available for whatever services you wish to pro= vide. Cheers, Matthew --=20 Dr Matthew J Seaman MA, D.Phil. 7 Priory Courtyard Flat 3 PGP: http://www.infracaninophile.co.uk/pgpkey Ramsgate Kent, CT11 9PW --------------enig58B1961704ED22B370E96E0F Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (FreeBSD) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFEeVj88Mjk52CukIwRA4VMAJ9LsJlAXXUurTrov/qWPm13uZlVYgCfWZo1 FsDs0p4U4WeOO7cLO106WLI= =Dbe0 -----END PGP SIGNATURE----- --------------enig58B1961704ED22B370E96E0F--