From owner-freebsd-jail@FreeBSD.ORG Sun May 8 01:49:32 2011 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E8F921065672 for ; Sun, 8 May 2011 01:49:32 +0000 (UTC) (envelope-from espartano.mail@gmail.com) Received: from mail-iy0-f182.google.com (mail-iy0-f182.google.com [209.85.210.182]) by mx1.freebsd.org (Postfix) with ESMTP id B1F598FC08 for ; Sun, 8 May 2011 01:49:32 +0000 (UTC) Received: by iyj12 with SMTP id 12so5050512iyj.13 for ; Sat, 07 May 2011 18:49:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=hzTk2sfI9NhP4h17Tw9+/JRjz6UytO2olLezpsklHHo=; b=Ghv6OaioPV4E29TpOW396kMRByn29MbBKZzddU+OJ6Z2/Zt01GLpvWaW1wy2roVRVk +A/twOZ4awCsjLYzlwvjiN8lZSW0JWxGtgRtsttQIV35hIF9VPxUivOgTJ7o9qGJK7i9 +nYBs5jt8gI9E4KdsciBn4eI18q1DV6WAaRPk= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=iTyffekUbajQHuytQZnfQiW0aS1v4nr4BuWHO5sIQbSRF/mKxVnT3AEtftgQbQEPcJ sGtd6DaiUow9OU1gAPN8x/C05SQfT/yDTkAn9NNkzJNOsSao3jQM+9tFcPaugC15t3YD jXhy2+RZUlxVGgzbtkSrckIyPO3IE34aR4KR4= MIME-Version: 1.0 Received: by 10.42.152.5 with SMTP id g5mr1748457icw.231.1304817984477; Sat, 07 May 2011 18:26:24 -0700 (PDT) Received: by 10.42.2.141 with HTTP; Sat, 7 May 2011 18:26:24 -0700 (PDT) In-Reply-To: <368245A4-1F9F-4D52-A64E-32993BB35E17@lists.zabbadoz.net> References: <368245A4-1F9F-4D52-A64E-32993BB35E17@lists.zabbadoz.net> Date: Sat, 7 May 2011 20:26:24 -0500 Message-ID: From: Espartano To: "Bjoern A. Zeeb" Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-jail@freebsd.org Subject: Re: pf or ipfw within a jail? X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 08 May 2011 01:49:33 -0000 On Fri, May 6, 2011 at 4:31 PM, Bjoern A. Zeeb wrote: > > On May 6, 2011, at 8:28 PM, Mickey Harvey wrote: > >> Is it possible to run pf or ipfw within a jail? I am running 8.2 and have >> vimage compiled in the kernel. > > ipfw might work then; pf not yet. ipfilter in a far distant future. > But ... Not VIMAGE project was developed exactly to allow has an virtual stack and allow to work firewalls like pf into a jail ?