Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 16 Aug 2016 15:44:54 +0000
From:      "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
To:        krad <kraduk@gmail.com>
Cc:        "freebsd-jail@freebsd.org" <freebsd-jail@freebsd.org>, "Freebsd Questions" <FreeBSD-questions@freebsd.org>
Subject:   Re: testing 11.0-RC1 vnet jails with ipfilter
Message-ID:  <F610E6D1-6622-4E15-98B4-F7AD58EEA9CF@lists.zabbadoz.net>
In-Reply-To: <CALfReyeR_4pM6FsrFZxTbHNoC1_yd3SZW72Ze9Bo354itzEgWQ@mail.gmail.com>
References:  <57B1E1BC.4090205@gmail.com> <078403E1-D8A3-4E52-B218-7A8B4400749A@lists.zabbadoz.net> <CALfReyeR_4pM6FsrFZxTbHNoC1_yd3SZW72Ze9Bo354itzEgWQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 16 Aug 2016, at 12:47, krad wrote:

> is ipfilter supported in vnet jails? Last time I looked and tried pf 
> didnt
> work (kernel panics), and only ipfw was supported.

In 11-RC* it is present for all 3 firewalls;  like VIMAGE due to memory 
footprint you might have to compile the firewall into the kernel rather 
than kldload it (especially ipfilter).

/bz



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F610E6D1-6622-4E15-98B4-F7AD58EEA9CF>