From owner-freebsd-questions@FreeBSD.ORG Sat Jul 30 05:25:43 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 86CCC16A41F for ; Sat, 30 Jul 2005 05:25:43 +0000 (GMT) (envelope-from cws@miraclenet.co.th) Received: from www.hotel-accommodation.net (www.hotel-accommodation.net [203.146.102.47]) by mx1.FreeBSD.org (Postfix) with ESMTP id ED98943D45 for ; Sat, 30 Jul 2005 05:25:42 +0000 (GMT) (envelope-from cws@miraclenet.co.th) Received: from secure.abatravel.net (localhost [127.0.0.1]) by www.hotel-accommodation.net (Postfix) with ESMTP id 0D5871DA2C for ; Sat, 30 Jul 2005 12:25:41 +0700 (ICT) Received: from 58.136.66.157 (SquirrelMail authenticated user cws) by secure.abatravel.net with HTTP; Sat, 30 Jul 2005 12:25:41 +0700 (ICT) Message-ID: <52771.58.136.66.157.1122701141.squirrel@secure.abatravel.net> Date: Sat, 30 Jul 2005 12:25:41 +0700 (ICT) From: "Chatchawan Wongsiriprasert" To: freebsd-questions@freebsd.org User-Agent: SquirrelMail/1.4.4 MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: 8bit X-Priority: 3 (Normal) Importance: Normal Subject: Acess 127.0.0.1 from FreeBSD jail X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 30 Jul 2005 05:25:43 -0000 Hi, I am now using chroot apache+php, and want to move to more secure FreeBSD jail. After read the FreeBSD handbook, I have been successfully created a jailed apache+php on my test server but there is a litle problem that need to be solved before I put it on my real server. I run mysql-server on this server and make it listen only to 127.0.0.1 (--bind-address option). How can I access mysql-server on this server from the jail without (1) make mysql-server listen to the real ip (I don't want to open another door to my server -- firewall can be employ but this add another complexity to my setup) or (2) using unix socket (a lot of code to change and test -- most are develop by another people). Regards, Chatchawan Wongsiriprasert