From owner-freebsd-questions@FreeBSD.ORG Sat Feb 26 01:11:33 2011 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E972A1065673 for ; Sat, 26 Feb 2011 01:11:33 +0000 (UTC) (envelope-from peter@vereshagin.org) Received: from mx1.skyriver.ru (ns1.skyriver.ru [89.108.118.221]) by mx1.freebsd.org (Postfix) with ESMTP id A5B188FC08 for ; Sat, 26 Feb 2011 01:11:33 +0000 (UTC) Received: from localhost (tor-exit-router40-readme.formlessnetworking.net [199.48.147.40]) by mx1.skyriver.ru (Postfix) with ESMTPSA id 76C8F5AAF; Sat, 26 Feb 2011 03:54:02 +0300 (MSK) Date: Sat, 26 Feb 2011 04:11:07 +0300 From: Peter Vereshagin To: freebsd-questions@freebsd.org Message-ID: <20110226011107.GA5308@external.screwed.box> References: <12e5c131918.-880143209072273718.-7160495597488262712@zoho.com> MIME-Version: 1.0 Content-Type: text/plain; charset=koi8-r Content-Disposition: inline In-Reply-To: <12e5c131918.-880143209072273718.-7160495597488262712@zoho.com> Organization: ' X-Face: 8T>{1owI$Byj]]a; ^G]kRf*dkq>E-3':F>4ODP[#X4s"dr?^b&2G@'3lukno]A1wvJ_L(~u 6>I2ra/<,j1%@C[LN=>p#_}RIV+#:KTszp-X$bQOj,K Cc: erikmccaskey64 Subject: Re: How can I disable Internet access for programs running in Wine? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 26 Feb 2011 01:11:34 -0000 Nothing to do oh, freebsd-questions stay in bat! 2011/02/25 01:07:58 -0800 erikmccaskey64 => To freebsd : e> I just can find any solution... I was sure that ipfw can select packets by process name? at least there are pf and ipf options out there... You can always use jail(4) in conjunction with the separate IP address, like tap(4) or lo(4) whic can be aliased. Then you can provide any kind of internet access for your wine-drunk jail environment ;-) Oh, and... you can use the / as a root for your jail. You need to restrict the access of the application(s) to your internet interface(s) only, right? 73! Peter pgp: A0E26627 (4A42 6841 2871 5EA7 52AB 12F8 0CE1 4AAC A0E2 6627) -- http://vereshagin.org