From owner-freebsd-security@FreeBSD.ORG Fri Dec 19 17:42:42 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0642B16A4CE for ; Fri, 19 Dec 2003 17:42:42 -0800 (PST) Received: from blurp.one.pl (21.t4.ds.pwr.wroc.pl [156.17.226.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id CC82B43D39 for ; Fri, 19 Dec 2003 17:42:40 -0800 (PST) (envelope-from gizmen@blurp.one.pl) Received: by blurp.one.pl (Postfix, from userid 1001) id AB321A0B; Sat, 20 Dec 2003 02:42:31 +0100 (CET) Date: Sat, 20 Dec 2003 02:42:31 +0100 From: GiZmen To: freebsd-security@FreeBSD.ORG Message-ID: <20031220014231.GA23229@blurp.one.pl> References: <20031219162648.GA76539@blurp.one.pl> <20031219170339.48E40D2@ken.ccs.sut.ru> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20031219170339.48E40D2@ken.ccs.sut.ru> User-Agent: Mutt/1.5.5.1i Subject: Re: Configuring JAIL to bind on lo0 interface X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 20 Dec 2003 01:42:42 -0000 > As i understood your problem you need addition alias on lo0 interface > for gateway ip purpose. So you have lo0 interface and lo0_alias0 > 192.168.1.1 as default gateway for jails. And now you create new jails' > ip as aliases on lo0 iface. > > For example: > > no jail, only gateway - lo0_alias0 192.168.1.1/24 > > jail1 - lo0_alias1 192.168.1.2/24 - hostname jail1.domain.com > in this jail set default gateway to 192.168.1.1 > > jail2 - lo0_alias2 192.168.1.3/24 - hostname jail2.domain.com > in this jail set default gateway to 192.168.1.1 also > > Your host machine have to be gateway enabled. > > Now if you want to switch on internet access from jail1 you only need to > add nat rule to translate jail1's ip to the host primary ip. > > Alesha. I dont know how can it work? AFAIK in jail i cant change the default gateway. -- Best Regards: GiZmen