From owner-freebsd-net@FreeBSD.ORG Sun Jan 6 11:27:32 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5E1DB16A46E for ; Sun, 6 Jan 2008 11:27:32 +0000 (UTC) (envelope-from freebsd@levsha.org.ua) Received: from expo.ukrweb.net (expo.ukrweb.net [193.125.78.116]) by mx1.freebsd.org (Postfix) with ESMTP id EE3E213C448 for ; Sun, 6 Jan 2008 11:27:31 +0000 (UTC) (envelope-from freebsd@levsha.org.ua) Received: from levsha by expo.ukrweb.net with local (Exim 4.68 (FreeBSD)) (envelope-from ) id 1JBTYP-000I6S-M8; Sun, 06 Jan 2008 13:20:33 +0200 Date: Sun, 6 Jan 2008 13:20:33 +0200 From: Mykola Dzham To: Julian Elischer Message-ID: <20080106112033.GA40991@expo.ukrweb.net> References: <4772F123.5030303@elischer.org> <477416CC.4090906@elischer.org> <477D2EF3.2060909@elischer.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <477D2EF3.2060909@elischer.org> X-Operating-System: FreeBSD/5.4-RELEASE-p6 (i386) User-Agent: Mutt/1.5.6i Cc: Qing Li , FreeBSD Net , arch@freebsd.org, Ivo Vachkov , Robert Watson , Vadim Goncharov Subject: Re: resend: multiple routing table roadmap (format fix) X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Jan 2008 11:27:32 -0000 Julian Elischer wrote: > > setfib 3 /bin/sh > > now by default everythign you do uses table 3. > or even > > setfib 3 jail {blah} > > and all the procs in the jail use table 3. You also need to do > setfib 3 jexec xxx > for extra processes you add to the jail afterwards. Is it possible to deny setfib after setfib N /bin/sh ? Or call setfib from jail? If yes this can be usable for restriction jail on some different fib -- Mykola Dzham, LEFT-(UANIC|RIPE) JID: levsha@jabber.net.ua