Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 16 Aug 2016 16:08:42 -0500
From:      CyberLeo Kitsana <cyberleo@cyberleo.net>
To:        Ernie Luzar <luzar722@gmail.com>, "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
Cc:        "freebsd-jail@freebsd.org" <freebsd-jail@freebsd.org>, Freebsd Questions <FreeBSD-questions@freebsd.org>, krad <kraduk@gmail.com>
Subject:   Re: testing 11.0-RC1 vnet jails with ipfilter
Message-ID:  <b640b4fa-ba88-9fde-41a0-339d9d4a897b@cyberleo.net>
In-Reply-To: <57B375C6.9030500@gmail.com>
References:  <57B1E1BC.4090205@gmail.com> <078403E1-D8A3-4E52-B218-7A8B4400749A@lists.zabbadoz.net> <CALfReyeR_4pM6FsrFZxTbHNoC1_yd3SZW72Ze9Bo354itzEgWQ@mail.gmail.com> <F610E6D1-6622-4E15-98B4-F7AD58EEA9CF@lists.zabbadoz.net> <57B375C6.9030500@gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 08/16/2016 03:21 PM, Ernie Luzar wrote:
<snip>
> Issuing "ipf -FS -Fa" command from within the vnet jail gives this
> message, "open device:no such file or directory. User kernel version
> check failed.

According to ipf(8), the ipfilter utilities touch /dev/ipauth , /dev/ipl
, and /dev/ipstate . Have you checked that the devfs ruleset applied to
your jail has those unhidden?

> Issuing "ipfstat -hnio command from within the vnet jail gives this
> message, open(IPSTATE_NAME):no such file or directory.

ipfstat(8) also lists /dev/kmem ; I suspect that including this may be a
bad idea.

-- 
Fuzzy love,
-CyberLeo
Technical Administrator
CyberLeo.Net Webhosting
http://www.CyberLeo.Net
<CyberLeo@CyberLeo.Net>

Furry Peace! - http://www.fur.com/peace/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?b640b4fa-ba88-9fde-41a0-339d9d4a897b>