From owner-freebsd-questions@FreeBSD.ORG Tue Jan 26 06:06:32 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3F271106566C for ; Tue, 26 Jan 2010 06:06:32 +0000 (UTC) (envelope-from tajudd@gmail.com) Received: from mail-px0-f183.google.com (mail-px0-f183.google.com [209.85.216.183]) by mx1.freebsd.org (Postfix) with ESMTP id 1612D8FC0C for ; Tue, 26 Jan 2010 06:06:31 +0000 (UTC) Received: by pxi13 with SMTP id 13so2996013pxi.3 for ; Mon, 25 Jan 2010 22:06:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type; bh=sicSveuOpBFZZKBuAl3Nmzio0DJ3SUdrPXs8TEFytcE=; b=tnlKnvDCTTF6IfyPS/LGWtw/H3Np03zjMTfktJ/ij67mCtgKAPfKz2K5iLS/uMEwWz zgE1HhNTVYMz64Hk1EzsCd1jNTak0yM+TQf6GBLPng2D4yfqaFpl4HqMZv5xF6gjHple XPwjM8wyraemq9v04rDQZO5XX16f3+izouD9M= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=R8uE7f4P1WPIdKP+XmKUKAs957bZMQTE6eULmQ2Nrcfz8jsgDyVGhXbZQ1jP4eFyK3 kUCqN3okqtRILkAuHjp0N6yVYkMYL5g5+Op6FsrdvqfTuFjJBD9POetChf6uE+V3EEWH hdT4S485LaWuMwe6uwHYMpQhZuAGCmhBBd7do= MIME-Version: 1.0 Received: by 10.115.101.40 with SMTP id d40mr3884009wam.95.1264485991112; Mon, 25 Jan 2010 22:06:31 -0800 (PST) In-Reply-To: <4B5E59DE.8050901@fusiongol.com> References: <20100124223626.37E5210656BD@hub.freebsd.org> <4B5D0639.4040503@fusiongol.com> <6201873e1001250729s36073a22t1c6f95bd2af7c2d4@mail.gmail.com> <4B5E59DE.8050901@fusiongol.com> Date: Mon, 25 Jan 2010 23:06:30 -0700 Message-ID: From: Tim Judd To: Nathan Butcher Content-Type: text/plain; charset=ISO-8859-1 Cc: Adam Vande More , freebsd-questions@freebsd.org Subject: Re: Raw sockets in jails X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 26 Jan 2010 06:06:32 -0000 On 1/25/10, Nathan Butcher wrote: > Thanks for the link. That clears a few things up, but not quite what I'm > trying to achieve.I set the following in rc.conf for a jail called "test" > > jail_test_flags="allow.raw_sockets" > > then I start the test jail with > > # /etc/rc.d/jail start test > > ... and then I get the following cryptic response... > > Configuring jails:. > Starting jails: cannot start jail "test": > But it doesn't look like one. > . > > ... and the jail doesn't start. > What's the story there? allowing raw sockets to a jail is a sysctl sysctl -a | grep "jail." the raw sockets tunable should easily be found. make the change permanent by editing/adding it to /etc/sysctl.conf --TJ