From owner-freebsd-net@FreeBSD.ORG Wed Dec 27 16:14:45 2006 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 8454016A40F for ; Wed, 27 Dec 2006 16:14:45 +0000 (UTC) (envelope-from tataz@tataz.chchile.org) Received: from postfix2-g20.free.fr (postfix2-g20.free.fr [212.27.60.43]) by mx1.freebsd.org (Postfix) with ESMTP id 3FB6F13C46D for ; Wed, 27 Dec 2006 16:14:45 +0000 (UTC) (envelope-from tataz@tataz.chchile.org) Received: from smtp7-g19.free.fr (smtp7-g19.free.fr [212.27.42.64]) by postfix2-g20.free.fr (Postfix) with ESMTP id 6F325845E23 for ; Wed, 27 Dec 2006 15:55:35 +0100 (CET) Received: from tatooine.tataz.chchile.org (tataz.chchile.org [82.233.239.98]) by smtp7-g19.free.fr (Postfix) with ESMTP id 6D4A7555A; Wed, 27 Dec 2006 16:55:31 +0100 (CET) Received: from obiwan.tataz.chchile.org (unknown [192.168.1.25]) by tatooine.tataz.chchile.org (Postfix) with ESMTP id 886BE9B465; Wed, 27 Dec 2006 15:56:38 +0000 (UTC) Received: by obiwan.tataz.chchile.org (Postfix, from userid 1000) id 630AC405B; Wed, 27 Dec 2006 16:56:38 +0100 (CET) Date: Wed, 27 Dec 2006 16:56:38 +0100 From: Jeremie Le Hen To: "Bjoern A. Zeeb" Message-ID: <20061227155638.GG2187@obiwan.tataz.chchile.org> References: <20061216094004.GA24480@harmless.hu> <20061216100556.T91892@maildrop.int.zabbadoz.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20061216100556.T91892@maildrop.int.zabbadoz.net> User-Agent: Mutt/1.5.13 (2006-08-11) Cc: Gergely CZUCZY , freebsd-net@freebsd.org Subject: Re: [fbsd] Re: jail addresses and default bindings X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 27 Dec 2006 16:14:45 -0000 On Sat, Dec 16, 2006 at 10:13:00AM +0000, Bjoern A. Zeeb wrote: > >this way it's hard to distingvish in a packet filter(let's say pf), > >among connections originating from within the jail itself or > >from the host system to the jail. > > I won't ask why you would want to do that if you control it > from the "host" system anyway... Additionally, ipfw(8) has the "jail" keyword, though it is easier to work with IP addresses since jail ids are bumped whenever you restart a jail. Regards, -- Jeremie Le Hen < jeremie at le-hen dot org >< ttz at chchile dot org >