From owner-freebsd-questions@FreeBSD.ORG Wed May 26 01:34:36 2010 Return-Path: Delivered-To: questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 049681065674 for ; Wed, 26 May 2010 01:34:36 +0000 (UTC) (envelope-from fbsd1@a1poweruser.com) Received: from mail-03.name-services.com (mail-03.name-services.com [69.64.155.195]) by mx1.freebsd.org (Postfix) with ESMTP id DE9948FC1C for ; Wed, 26 May 2010 01:34:35 +0000 (UTC) Received: from [10.0.10.3] ([202.69.172.54]) by mail-03.name-services.com with Microsoft SMTPSVC(6.0.3790.3959); Tue, 25 May 2010 18:34:35 -0700 Message-ID: <4BFC7AA4.8020009@a1poweruser.com> Date: Wed, 26 May 2010 09:34:28 +0800 From: Fbsd1 User-Agent: Thunderbird 2.0.0.17 (Windows/20080914) MIME-Version: 1.0 To: =?ISO-8859-1?Q?Bal=E1zs_M=E1t=E9ffy?= References: <4BFC5EE3.3090505@a1poweruser.com> In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 8bit X-OriginalArrivalTime: 26 May 2010 01:34:35.0906 (UTC) FILETIME=[996E4620:01CAFC73] X-Sender: fbsd1@a1poweruser.com Cc: questions@freebsd.org Subject: Re: jails and one dynamic ip address X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 26 May 2010 01:34:36 -0000 >> I get one dynamic ip address from my ISP. This is what I specify on the >> jail for public network access. When the ip address changes on me I have to >> manually change the ip address associated with the jail. >> >> Is there some method I can code so jail will all ways have public network >> access? > Hi, > > > Sure there can be a better solution (I think :)): > > Use an rfc1918 private address range for your Jail, and use nat, to > forward your external interface IP to the private address of the jail. > > This can be done in ipnat, PF, or the other natting, packet filtering > tools. > > Hope I understood your question :). > > Regards, > > Balázs M. > The jails are on the host with LAN behind it and with ipf firewall which allows out anything coming from LAN private ip address. I was not able to get this to work until I discovered the jail needed a copy of the hosts /etc/resolv.conf. Now it works without any special tweaks, and the dymanic ip address changing causes no problems.