From owner-freebsd-hackers@freebsd.org Sun Mar 6 12:15:24 2016 Return-Path: Delivered-To: freebsd-hackers@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E5FBD9DA585 for ; Sun, 6 Mar 2016 12:15:24 +0000 (UTC) (envelope-from afiskon@devzen.ru) Received: from relay12.nicmail.ru (relay12.nicmail.ru [195.208.5.7]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 9BA0DA96 for ; Sun, 6 Mar 2016 12:15:24 +0000 (UTC) (envelope-from afiskon@devzen.ru) Received: from [31.177.73.174] (port=54551 helo=nicmail.ru) by f06.mail.nic.ru with esmtp (Exim 5.55) (envelope-from ) id 1acXas-0007LD-1b; Sun, 06 Mar 2016 15:15:30 +0300 Received: from [10.0.6.224] (account afiskon@devzen.ru HELO fujitsu) by fcgp24.nicmail.ru (CommuniGate Pro SMTP 5.2.3) with ESMTPA id 70748480; Sun, 06 Mar 2016 15:15:21 +0300 Received: from [188.123.231.37] (account afiskon@devzen.ru HELO fujitsu) by proxy04.mail.nic.ru (Exim 5.55) with id 1acXaj-0003w7-Px; Sun, 06 Mar 2016 15:15:21 +0300 Date: Sun, 6 Mar 2016 15:12:40 +0300 From: Eax Melanhovich To: Kamila =?UTF-8?B?U291xI1rb3bDoQ==?= Cc: freebsd-hackers@freebsd.org Subject: Re: Looking for security-related intro project Message-ID: <20160306151240.5be6fc41@fujitsu> In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Mar 2016 12:15:25 -0000 Hello, Kamila I personally find networking in FreeBSD Jails (this feature is considered security related, right?) not particularly user friendly. It would be nice to have something similar to how LXC and OpenVZ works. You just say "create container" and voila --- container has access to the Internet and you also have host-guest system networking. All of this is by default. No static IPs or anything else is required. Sounds like a good idea for security-related project to me. -- Best regards, Eax Melanhovich http://eax.me/