From owner-freebsd-jail@freebsd.org Fri Dec 11 22:10:43 2015 Return-Path: Delivered-To: freebsd-jail@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 50B289D72FD for ; Fri, 11 Dec 2015 22:10:43 +0000 (UTC) (envelope-from 000.fbsd@quip.cz) Received: from elsa.codelab.cz (elsa.codelab.cz [94.124.105.4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 173591F32 for ; Fri, 11 Dec 2015 22:10:42 +0000 (UTC) (envelope-from 000.fbsd@quip.cz) Received: from elsa.codelab.cz (localhost [127.0.0.1]) by elsa.codelab.cz (Postfix) with ESMTP id 0697E28469; Fri, 11 Dec 2015 23:10:33 +0100 (CET) Received: from illbsd.quip.test (ip-86-49-16-209.net.upcbroadband.cz [86.49.16.209]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by elsa.codelab.cz (Postfix) with ESMTPSA id 54DB528451; Fri, 11 Dec 2015 23:10:32 +0100 (CET) Message-ID: <566B49D8.8030206@quip.cz> Date: Fri, 11 Dec 2015 23:10:32 +0100 From: Miroslav Lachman <000.fbsd@quip.cz> User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:35.0) Gecko/20100101 Firefox/35.0 SeaMonkey/2.32 MIME-Version: 1.0 To: Rob J , freebsd-jail@freebsd.org Subject: Re: ppp has NOJAIL keyword in its startup script References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Dec 2015 22:10:43 -0000 Rob J wrote on 12/11/2015 20:26: > Hello, > I was wondering why my ppp configuration wasn't starting in a jail, > until I looked at the /etc/rc.d/ppp script, which contains the keyword > NOJAIL. > > So, I cannot start ppp (for my dsl connection) in a jail, and the > question is why? Are there security, or other reasons why you can't > run ppp in a jail? You cannot manage network interfaces, IP addresses and routing tables in jail with default system settings. (for security reason) Miroslav Lachman