From owner-freebsd-questions Mon Jan 29 4:34:51 2001 Delivered-To: freebsd-questions@freebsd.org Received: from d9168.upc-d.chello.nl (d9168.upc-d.chello.nl [213.46.9.168]) by hub.freebsd.org (Postfix) with ESMTP id F2BA237B402 for ; Mon, 29 Jan 2001 04:34:31 -0800 (PST) Received: by d9168.upc-d.chello.nl (Postfix, from userid 1001) id AC83018B; Mon, 29 Jan 2001 13:34:30 +0100 (CET) Date: Mon, 29 Jan 2001 13:34:30 +0100 From: Edwin Groothuis To: Mark Livingstone Cc: freebsd-questions@freebsd.org Subject: Re: JAIL!!!!!!! do you know?! Message-ID: <20010129133430.H62745@d9168.upc-d.chello.nl> Mail-Followup-To: Edwin Groothuis , Mark Livingstone , freebsd-questions@freebsd.org References: <001701c089ed$891c4680$0200a8c0@vvk> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <001701c089ed$891c4680$0200a8c0@vvk>; from mlivingstone@ottawa.com on Mon, Jan 29, 2001 at 07:18:06AM -0500 Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG On Mon, Jan 29, 2001 at 07:18:06AM -0500, Mark Livingstone wrote: > Im a bit confused as to which ip to use. My box has 1 external ip (to > internet) and one internal (to server internal computers). I want to set up > jail so that all incoming ssh connections to external ip would be placed > into jail. What should i use as an ip? Then start a jail and sshd in it :-) I'm not sure if you can't make any outgoing connection after that,but it works like you wanted :-) > Perhpas someone has a good link also to the whole procedure of setting up > jail. I found the jail-manpage good enough to do some tests for myself and all worked like a charm. > Are there any disadvantages of having jailed system?! What kind of things are you thinking of? Edwin -- Edwin Groothuis | Interested in MUDs? Visit Fatal Dimensions: mavetju@chello.nl | http://fataldimensions.nl.eu.org/ ------------------+ telnet://fataldimensions.nl.eu.org:4000 To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message