From owner-freebsd-questions@freebsd.org Wed Mar 18 15:35:46 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 38125263757 for ; Wed, 18 Mar 2020 15:35:46 +0000 (UTC) (envelope-from 4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 48jDdW6bg2z3PQk for ; Wed, 18 Mar 2020 15:35:43 +0000 (UTC) (envelope-from 4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1584545744; x=1587137744; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:cc:to:from:date:x-thread-info; bh=tBgXcmyrB57JVVztcMEzo/Qug67y5lOLN+a3s/KAj8w=; b=uzIUVfPTlAW7nEOnSglmW7+OwsyUgOwoW0OO4UCempvgGTqpuY5NWUxZVgFrmbm0AZFrH9hDu6O3pvAoRzrNQZbAtytvEVMlN9hlX/1Dybv+vY9QWO6mHkzJy9cUbiAYVFi5gdRREqsNAd/FrV5KdRNDQl6oowUuHQL1st0SYIE= X-Thread-Info: NDI1MC45Mi4xZDRjMDAwMDA3N2FmNmMuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r3.sg.in.socketlabs.com (r3.sg.in.socketlabs.com [142.0.179.13]) by mxsg2.email-od.com with ESMTP; Wed, 18 Mar 2020 11:35:38 -0400 Received: from smtp.lan.sohara.org (EMTPY [185.202.17.215]) by r3.sg.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Wed, 18 Mar 2020 11:35:37 -0400 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.92.3 (FreeBSD)) (envelope-from ) id 1jEajH-000Frf-OB; Wed, 18 Mar 2020 15:35:35 +0000 Date: Wed, 18 Mar 2020 15:35:35 +0000 From: Steve O'Hara-Smith To: Victor Sudakov Cc: freebsd-questions@freebsd.org, freebsd-net@freebsd.org Subject: Re: IPv6 in jails Message-Id: <20200318153535.1a91d84f145e634594e6aca7@sohara.org> In-Reply-To: <20200318151556.GA64871@admin.sibptus.ru> References: <20200318151556.GA64871@admin.sibptus.ru> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.32; amd64-portbld-freebsd12.0) X-Clacks-Overhead: "GNU Terry Pratchett" Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 48jDdW6bg2z3PQk X-Spamd-Bar: + Authentication-Results: mx1.freebsd.org; dkim=pass header.d=email-od.com header.s=dkim header.b=uzIUVfPT; dmarc=none; spf=pass (mx1.freebsd.org: domain of 4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com designates 142.0.176.198 as permitted sender) smtp.mailfrom=4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com X-Spamd-Result: default: False [1.79 / 15.00]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[email-od.com:s=dkim]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; MV_CASE(0.50)[]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[sohara.org]; TO_DN_SOME(0.00)[]; NEURAL_SPAM_MEDIUM(0.87)[0.866,0]; RCVD_COUNT_THREE(0.00)[4]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[email-od.com:+]; NEURAL_SPAM_LONG(0.53)[0.528,0]; RCVD_IN_DNSWL_NONE(0.00)[198.176.0.142.list.dnswl.org : 127.0.15.0]; IP_SCORE(0.09)[ip: (-0.25), ipnet: 142.0.176.0/22(0.51), asn: 7381(0.26), country: US(-0.05)]; FORGED_SENDER(0.30)[steve@sohara.org,4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.82.1d4c0000077af6c.3c6503bf8eaafcc31ed82c7fb0777ab6@email-od.com]; MID_RHS_MATCH_FROM(0.00)[] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 18 Mar 2020 15:35:46 -0000 On Wed, 18 Mar 2020 22:15:56 +0700 Victor Sudakov wrote: > If I "ssh 2001:470:ecba:3::4" from outside, I get into the host instead > of the jail (because 2001:470:ecba:3::4 *is* assigned to re1, but not > available inside the jail). Having the host listening on an address will stop any jails from being able to listen on that address. You need to stop the host services listening on the jail's IPv6 address. -- Steve O'Hara-Smith