From owner-freebsd-security@FreeBSD.ORG Fri Aug 26 14:41:23 2005 Return-Path: X-Original-To: freebsd-security@FreeBSD.org Delivered-To: freebsd-security@FreeBSD.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CA28316A41F; Fri, 26 Aug 2005 14:41:23 +0000 (GMT) (envelope-from bra@fsn.hu) Received: from people.fsn.hu (people.fsn.hu [195.228.252.137]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3065D43D45; Fri, 26 Aug 2005 14:41:22 +0000 (GMT) (envelope-from bra@fsn.hu) Received: from localhost (localhost [127.0.0.1]) by people.fsn.hu (Postfix) with ESMTP id 0B8EE8441E; Fri, 26 Aug 2005 16:41:20 +0200 (CEST) Received: from people.fsn.hu ([127.0.0.1]) by localhost (people.fsn.hu [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 59952-01-3; Fri, 26 Aug 2005 16:41:13 +0200 (CEST) Received: from [172.16.129.72] (japan.t-online.co.hu [195.228.243.99]) by people.fsn.hu (Postfix) with ESMTP id 7795C8441F; Fri, 26 Aug 2005 16:41:13 +0200 (CEST) Message-ID: <430F2A09.5000301@fsn.hu> Date: Fri, 26 Aug 2005 16:41:13 +0200 From: Attila Nagy User-Agent: Mozilla Thunderbird 1.0.6 (X11/20050725) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Anders Nordby References: <20050826103310.GA94494@totem.fix.no> In-Reply-To: <20050826103310.GA94494@totem.fix.no> Content-Type: text/plain; charset=ISO-8859-2; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: amavisd-new at fsn.hu Cc: freebsd-net@FreeBSD.org, freebsd-security@FreeBSD.org Subject: Re: Filtering jail IP traffic X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Aug 2005 14:41:23 -0000 Anders Nordby wrote: > IP traffic from one jail to another jail, arrives on destination jail on > lo0 having the destination jails IP as source IP. Why not the source > jail's IP address? > How can I filter traffic from one jail to another, using ipfw of ipf? AFAIK (at least with pf), you can't really filter on loopback interfaces. Last time I tried, I could not filter on TCP or UDP ports, filtering from and to IP and protocol worked. -- Attila Nagy e-mail: Attila.Nagy@fsn.hu Adopt a directory on our free software phone @work: +361 371 3536 server! http://www.fsn.hu/?f=brick cell.: +3630 306 6758