Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 6 Jan 2009 17:03:33 +0100
From:      Albert Shih <Albert.Shih@obspm.fr>
To:        "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
Cc:        freebsd-jail@FreeBSD.org
Subject:   Re: Nagios & Jail
Message-ID:  <20090106160333.GA99388@obspm.fr>
In-Reply-To: <20090106150352.B45399@maildrop.int.zabbadoz.net>
References:  <20081217210542.GA25347@obspm.fr> <20081218172218.GE3080@home.opsec.eu> <20090106145716.GE94159@obspm.fr> <20090106150352.B45399@maildrop.int.zabbadoz.net>

next in thread | previous in thread | raw e-mail | index | archive | help
 Le 06/01/2009 à 15:06:37+0000, Bjoern A. Zeeb a écrit
> On Tue, 6 Jan 2009, Albert Shih wrote:
> 
> > In fact I found the problem :
> >
> > When I compile nagios-plugin ports in a jail the «configure» don't find
> > syntax of ping :
> >
> > checking for ping... /sbin/ping
> > checking for ping6... /sbin/ping6
> > checking for ICMP ping syntax... configure: WARNING: unable to find usable ping syntax
> >
> > But if I compile the same ports in a «normal» server (both are amd64).
> >
> > checking for ping... /sbin/ping
> > checking for ping6... /sbin/ping6
> > checking for ICMP ping syntax... /sbin/ping -n -c %d %s
> > checking for ICMPv6 ping syntax... /sbin/ping6 -n -c %d %s
> >
> > So if I use the check_ping produce by compiling in a no-jail server on a
> > jail-server it's working.
> >
> > I think it's a bug about the nagios-plugins ports. What you think ?
> 
> I think most of all configure stuff out there is ... ok, if you
> compile the port inside a jail and permit raw sockets, does it work
> then -- 
> either by using the rc.conf option and restarting the jail with
> rc.d/jail or using sysctl security.jail.allow_raw_sockets=1  ?

You mean I MUST restart the jail after I change the sysctl value ? Because
after I change it, I can make a ping from inside the jail without
restarting the jail.

Well I'm going to make a new jail to check that (all other jail is in
production). 

> 
> It smells it tries to execute a ping command and that does not
> succeed.

Yes. I agree.

Regards.


-- 
Albert SHIH
SIO batiment 15
Observatoire de Paris Meudon
5 Place Jules Janssen
92195 Meudon Cedex
Heure local/Local time:
Mar 6 jan 2009 17:02:12 CET



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20090106160333.GA99388>