From owner-freebsd-jail@FreeBSD.ORG Wed May 1 16:51:52 2013 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id BAB7AE4A for ; Wed, 1 May 2013 16:51:52 +0000 (UTC) (envelope-from smithi@nimnet.asn.au) Received: from sola.nimnet.asn.au (paqi.nimnet.asn.au [115.70.110.159]) by mx1.freebsd.org (Postfix) with ESMTP id 370721904 for ; Wed, 1 May 2013 16:51:51 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by sola.nimnet.asn.au (8.14.2/8.14.2) with ESMTP id r41GUJ6n031788; Thu, 2 May 2013 02:30:19 +1000 (EST) (envelope-from smithi@nimnet.asn.au) Date: Thu, 2 May 2013 02:30:19 +1000 (EST) From: Ian Smith To: Joe Subject: Re: vnet jail with ipfw having logging problem In-Reply-To: <51805EFB.6050806@a1poweruser.com> Message-ID: <20130502021830.O30818@sola.nimnet.asn.au> References: <44AC45947DA14449AEDFB13B9F6C5F7DAF3E1FA5@ltcfiswmsgmb25> <517A7BCB.8060604@a1poweruser.com> <13CA24D6AB415D428143D44749F57D7201F22068@ltcfiswmsgmb21> <517D3426.1090703@a1poweruser.com> <51805EFB.6050806@a1poweruser.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Cc: freebsd-jail X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 01 May 2013 16:51:52 -0000 On Tue, 30 Apr 2013 20:16:59 -0400, Joe wrote: > I have ipfw running inside of a vnet jail on a 9.1-RELEASE host using the > jail(8) definition statements for starting and stopping the vnet jail. As a > side note non-vnet jails are working as expected. > > The host is running a custom kernel with modules and with > options VIMAGE > nooptions SCTP > options IPFIREWALL > options IPFIREWALL_VERBOSE > options IPFIREWALL_VERBOSE_LIMIT=10 What steps have you taken during testing to override this ridiculously low limit on logging? Otherwise, after e.g. just 5 pings and 5 ping responses are logged, all logging ceases until issuing 'ipfw resetlog'. > options IPFIREWALL_DEFAULT_TO_ACCEPT > options IPFIREWALL_IPDIVERT You'd likely do better using in-kernel NAT; natd doesn't get much love. > options IPFIREWALL_FORWARD > > compiled in. Ian