From owner-freebsd-stable@FreeBSD.ORG Fri Nov 23 06:22:32 2012 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 29016FF8 for ; Fri, 23 Nov 2012 06:22:32 +0000 (UTC) (envelope-from morgan.s.reed@gmail.com) Received: from mail-ia0-f182.google.com (mail-ia0-f182.google.com [209.85.210.182]) by mx1.freebsd.org (Postfix) with ESMTP id DE4B88FC08 for ; Fri, 23 Nov 2012 06:22:31 +0000 (UTC) Received: by mail-ia0-f182.google.com with SMTP id x2so7891393iad.13 for ; Thu, 22 Nov 2012 22:22:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type; bh=tL1xY1MvntBqAl0gxXpZuhHl5FN46BYLSgbx6/GzTkM=; b=Nz5tYlNxoeczQgBSMwoNfZb0zIWx5GM1vI6jEjtBBAz+xunhsvUwyTeG6GtDegXANO JKY0G3HU4Riz8T7gi+VYYJLRThL/Lpv0SpqLCbI3lyFyYMyT6VXXnjOUKrFE5U4jujWN iV8wG8gTj6lvX64ILoHbY9fDSCy5Gp2iNWDocH3RE0sTvgtkc6lAuZ4nuNm0/PsARvLD 5eTnCJTncDbW9C6+5m993JgkX10pPxXsoQZQzp58fmOQOFOAKFLUTsZSHy5PNmAgEE8u guFE9yiCTwt+LYE6sPf7UWRiTINYnfQsKVZ0LFknAcZKRnzvRosAxp7wn2E10NwyBUNV gCBw== Received: by 10.50.187.134 with SMTP id fs6mr5181805igc.61.1353651751366; Thu, 22 Nov 2012 22:22:31 -0800 (PST) MIME-Version: 1.0 Received: by 10.64.6.71 with HTTP; Thu, 22 Nov 2012 22:22:11 -0800 (PST) In-Reply-To: References: From: Morgan Reed Date: Fri, 23 Nov 2012 17:22:11 +1100 Message-ID: Subject: Re: natd in a jail To: Dewayne Geraghty , freebsd-stable@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Nov 2012 06:22:32 -0000 On Fri, Nov 23, 2012 at 5:16 PM, Morgan Reed wrote: > So it turns out I'd not bought bpf into the jails, however even with > that and raw_sockets enabled I'm still having no joy with natd. > > I've been looking at ipfw a bit today but I've run into an issue, > loading ipfw_nat causes my kernel to instantly panic, I need to > recompile with KDB and DDB turned on so I can actually catch the trace > though... Might look at netgraph before going too far down that path. Scratch that, netgtaph isn't in the GENERIC kernel, so I'll have to rebuild anyway.