From nobody Mon Jun 30 03:09:46 2025 X-Original-To: freebsd-net@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4bVrk445fKz5yqw8 for ; Mon, 30 Jun 2025 03:09:48 +0000 (UTC) (envelope-from mason@blisses.org) Received: from yangtze.blisses.org (yangtze.blisses.org [144.202.50.44]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4bVrk36szgz3ngB for ; Mon, 30 Jun 2025 03:09:47 +0000 (UTC) (envelope-from mason@blisses.org) Authentication-Results: mx1.freebsd.org; none Received: from contoocook.blisses.org (contoocook.blisses.org [68.238.57.52]) by yangtze.blisses.org (Postfix) with ESMTP id 5FD8B182A47; Sun, 29 Jun 2025 23:09:47 -0400 (EDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=blisses.org; s=default; t=1751252454; bh=t1F1dZMbzyKQ5owrCr1NnEVs27lc2Ndp9+RcxO2Xa28=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=apssJ8GYrJZOXXfyAbdWTJQYQjuN72r1aUBji0nyPMASQMRVIKqhz3QvQJU6WQdbR Mvgdnfw4WoX6HILwzdWchMrKmygnZMPwnTsEjApOgBwYlPCYcOz819DNYb0ukgsFxy 8xxVFscMPD70Dvhjr4wcvD3jKiFiFKbdZSsS83xFm6FV0KQK13ZF8MclQEbVWBglEN LxLcsNmCAI59s7Vg1+Lp9NWID9lVvdGEcLp8jlkPCzTrsiBSdv/WgR7zojig812cQ5 FY/UrHc/55HfeZYDCKRXHY0lXFcK2eCYYdciTozlIcbU20qFS0nf1oIiTLqqQ5ea1i PPo82kfQrb+og== Date: Sun, 29 Jun 2025 23:09:46 -0400 From: Mason Loring Bliss To: Paul Procacci Cc: freebsd-net@freebsd.org Subject: Re: rp_filter equivalent? Message-ID: References: List-Id: Networking and TCP/IP with FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-net List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-net@FreeBSD.org MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="/vJ/SezkX+9QSQLs" Content-Disposition: inline In-Reply-To: X-Rspamd-Queue-Id: 4bVrk36szgz3ngB X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:20473, ipnet:144.202.48.0/20, country:US] --/vJ/SezkX+9QSQLs Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Jun 29, 2025 at 10:55:49PM -0400, Paul Procacci wrote: > Ok, I misunderstood what you initially wrote because the language you're > using isn't exactly what I'd expect in the world of networking. I'm only peripherally a networking person, so I'm not surprised. > To clear up any confusion ... you have two ip addresses, each one > being in different subnets. Yes. > The ip assigned to the host and the gateway that the host talks to are > in one subnet while the other ip address assigned to the jail/vnet is > in an entirely different subnet. And yes. > Using VNET, you can try the following within the jail but I've never trie= d: > route add -net w.x.y.z/mask a.b.c.1 > route add default a.b.c.1 I'll try that. That's what I remember trying initially, but unsuccessfully, although I don't know that I included a subnet mask for w.x.y.z. It was a month and a half ago and I was thrashing around through a number of options, so I'll try it again this week and document things more closely. Thank you! --=20 (defun main () (format t "Mason Loring Bliss - mason@blisses.org - ") (format t "By the mysgydynge of the sterysman, he was set vpon the pylys") (format t " of the brydge, and the barge whelmyd. - Chronicle of Fabyan~%"= )) --/vJ/SezkX+9QSQLs Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEXtBZz1axB5rEDCEnrJXcHbvJVUFAmhh//gACgkQnrJXcHbv JVXiDg/+Ix+krFqWSBcJ/gGQuawSNQhFZzo4g6wzNzoG7M8NiuNcN0+uwgqVUEQ4 GghsOq/YCsK3o9+52ZLcwmqN75qQpcWdirxQVPu+2SaydRlUBuVKHzB+oGDaJBQB aZBbWuq/5Wz08nxKWVjHKUIcA1nAlwqvfRR5s16LV83kBNOUqJ7qyzn1y9jaP2xq UqYRfjVPYoXTNzZN3nRj9BylvMjoZ8OdT1h6xEuQpABu/gZ/ORt61e6iBTQmnpMt OYVi+o9ns9wGkGpGwDzu1f+kqIZhTYEKuJtgXvSXyj71/HF/b69+5g78TqBZSuLa y4r+8C8NMmGUKIx0CgCwMGPPOXpR/RFYED1b7FryEkbiKNW1zv+M7iNcEc2jI3KM 0pnl2E2oqkh+z/YMPyM/rbCVYd3z2xcYI2HoDrLkk4rjaIH7G/HQgHnpg73jSgXY wbVhtt9KJ9t2UH5eO3aCd6FIO4fMXGpvmvdWvVxd50SQ8q4F6rpZJHDIB319vyQV 26aanv1xT0mEHeCcoHr/Vjzxig34hxm4VCiTViETgj0KZS2WZ/zR3CyNO2O7apaC BF38plzbrZkHfyEInjUXxrZIDaWv7qvMOJlkxeHraPoNQeaicQ8+ohEH4e7SWU+T Rr2TBQYwDUDF4di4GAMdmrloearVtcE4CNOkxKTdDaJDKHQx2nY= =cKDz -----END PGP SIGNATURE----- --/vJ/SezkX+9QSQLs--