Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 25 May 2008 22:47:55 +0100
From:      "Steven Hartland" <killing@multiplay.co.uk>
To:        "Geoffroy DESVERNAY" <dgeo@ec-marseille.fr>, <freebsd-jail@freebsd.org>
Subject:   Re: Jail resource limits
Message-ID:  <1F08E6231F60497A9BF556590BB56E9A@multiplay.co.uk>
References:  <822C1BB6-3591-4CE1-AFEA-8B07B9F5ED8D@pean.org><483556DB.9070602@quip.cz><08244555-5BD2-4F67-B311-CCC5E316A068@pean.org>	<20080522165219.D47338@maildrop.int.zabbadoz.net> <8068148B75CB4B3E953144A0DF47E496@multiplay.co.uk> <4839CEFC.1050605@ec-marseille.fr>

next in thread | previous in thread | raw e-mail | index | archive | help
----- Original Message ----- 
From: "Geoffroy DESVERNAY" <dgeo@ec-marseille.fr>
>> This is something we're really looking forward to tbh a great
>> feature :) One of the reasons for this is hosting jails, with
>> the addition of multi IP support we will be able to enable
>> jails to connect to "backdoor" secure services such as a
>> mysql server.
>> 
> We are already doing this (sql on a separated(physical) LAN, but jail
> don't need a second interface for that: the real host's routing table is
> used for outgoing packets.
> Note we still need a static route on the SQL server for the packets to
> come back the same way
> 
> I still don't know if this behaviour is the better one (one may think
> that jail's packets should not go through different interface ?), but it
> works quite well ;)

Surely that compromises jail security i.e. being able to access
resources from the host box even it the jail has no perceivable
access to them?

I assume this still doesn't work if the server is in fact run on
the main host only running on localhost?

    Regards
    Steve

================================================
This e.mail is private and confidential between Multiplay (UK) Ltd. and the person or entity to whom it is addressed. In the event of misdirection, the recipient is prohibited from using, copying, printing or otherwise disseminating it or any information contained in it. 

In the event of misdirection, illegible or incomplete transmission please telephone +44 845 868 1337
or return the E.mail to postmaster@multiplay.co.uk.




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1F08E6231F60497A9BF556590BB56E9A>