From nobody Sat Feb 19 10:04:17 2022 X-Original-To: freebsd-questions@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id DF45F19C2E88 for ; Sat, 19 Feb 2022 10:04:34 +0000 (UTC) (envelope-from 4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4K140x6qN5z3jwB for ; Sat, 19 Feb 2022 10:04:33 +0000 (UTC) (envelope-from 4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1645265074; x=1647857074; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:cc:to:from:date:x-thread-info; bh=fVIVm5XtOIU4yaTZCBdPqB/zDGBAhPUTKZ8shAQOlwE=; b=rZzjk07pJf04kJ6BGd93EOdi5ejazgQ1jl6nc9jKYtrwJSZK7dBHcln1BVNAGem8ysFhrWyncy2PPxrEBiHTvks/hpQ04YECArwYlbE6IBFt42JBmuo6iMKW91eLmXxY0hfmc6jXRp8wDAmQFonIe+WeVHpm4rYAkMSzN3UvrsE= X-Thread-Info: NDI1MC4xMi4xZDRkYjAwMDA4OTZiYTIuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r1.us-east-1.aws.in.socketlabs.com (r1.us-east-1.aws.in.socketlabs.com [142.0.191.1]) by mxsg2.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Sat, 19 Feb 2022 05:04:20 -0500 Received: from smtp.lan.sohara.org (EMTPY [185.202.17.215]) by r1.us-east-1.aws.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Sat, 19 Feb 2022 05:04:18 -0500 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.94.2 (FreeBSD)) (envelope-from ) id 1nLMbB-000Dd3-OF; Sat, 19 Feb 2022 10:04:17 +0000 Date: Sat, 19 Feb 2022 10:04:17 +0000 From: Steve O'Hara-Smith To: Steve Kirk Cc: FreeBSD Questions Subject: Re: local-unbound in a jail Message-Id: <20220219100417.925196fc031684c78cdc8d9f@sohara.org> In-Reply-To: References: X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.33; amd64-portbld-freebsd13.0) X-Clacks-Overhead: "GNU Terry Pratchett" List-Id: User questions List-Archive: https://lists.freebsd.org/archives/freebsd-questions List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-questions@freebsd.org X-BeenThere: freebsd-questions@freebsd.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 4K140x6qN5z3jwB X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=email-od.com header.s=dkim header.b=rZzjk07p; dmarc=none; spf=pass (mx1.freebsd.org: domain of 4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com designates 142.0.176.198 as permitted sender) smtp.mailfrom=4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com X-Spamd-Result: default: False [-2.67 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-0.97)[-0.969]; R_DKIM_ALLOW(-0.20)[email-od.com:s=dkim]; FROM_HAS_DN(0.00)[]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[sohara.org]; NEURAL_HAM_LONG(-1.00)[-1.000]; RCVD_COUNT_THREE(0.00)[4]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_ALL(0.00)[]; DKIM_TRACE(0.00)[email-od.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[142.0.191.1:received]; NEURAL_HAM_SHORT(-1.00)[-1.000]; MLMMJ_DEST(0.00)[freebsd-questions]; FORGED_SENDER(0.30)[steve@sohara.org,4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.82.1d4db0000896ba2.f4e077bcee984f39dca2b9e76a1eb9c0@email-od.com]; MID_RHS_MATCH_FROM(0.00)[]; DWL_DNSWL_NONE(0.00)[email-od.com:dkim] X-ThisMailContainsUnwantedMimeParts: N On Fri, 18 Feb 2022 17:02:45 +0000 Steve Kirk wrote: > Afternoon all, > > I suspect that I know the answer to this question, however... I have > tried to run local-unbound in a jail (as I intend to run rspamd in said > jail) but it seems like it doesn't play nicely because there's no > loopback address *inside* the jail which is the only interface this > service is designed to work with. Setting up a cloned loopback on lo1 etc for jails is common practice, does that not work for local unbound ? The technique is described under ezjail in the handbook but it can be used without using ezjail. -- Steve O'Hara-Smith