From owner-freebsd-questions@FreeBSD.ORG Tue Jul 8 17:02:08 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C27B91065695 for ; Tue, 8 Jul 2008 17:02:08 +0000 (UTC) (envelope-from www@rulez.sk) Received: from mailhub.rulez.sk (mailhub.rulez.sk [78.47.53.106]) by mx1.freebsd.org (Postfix) with ESMTP id 7CFA38FC2B for ; Tue, 8 Jul 2008 17:02:08 +0000 (UTC) (envelope-from www@rulez.sk) Received: from localhost (localhost [127.0.0.1]) by mailhub.rulez.sk (Postfix) with ESMTP id 0D01B5C04E; Tue, 8 Jul 2008 18:44:32 +0200 (CEST) X-Virus-Scanned: amavisd-new at rulez.sk Received: from mailhub.rulez.sk ([78.47.53.106]) by localhost (genesis.rulez.sk [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UpVSOhrNxdaJ; Tue, 8 Jul 2008 18:44:30 +0200 (CEST) Received: by mailhub.rulez.sk (Postfix, from userid 80) id BB8F15C050; Tue, 8 Jul 2008 18:44:30 +0200 (CEST) To: Matthew Seaman MIME-Version: 1.0 Date: Tue, 08 Jul 2008 18:44:30 +0200 From: Daniel Gerzo Organization: The FreeBSD Project In-Reply-To: <4873973D.1080402@infracaninophile.co.uk> References: <2daa8b4e0807070951u607ff031v98b5b96103fdab4@mail.gmail.com> <200807081124.33377.fbsd.questions@rachie.is-a-geek.net> <2daa8b4e0807080903o609d6b7ag831845b7939c20c8@mail.gmail.com> <4873973D.1080402@infracaninophile.co.uk> Message-ID: <5587447de8c610cd6e2a0a3ee7685f8d@78.47.53.106> X-Sender: danger@FreeBSD.org User-Agent: RoundCube Webmail/0.1 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit Cc: Mel , David Allen , freebsd-questions@freebsd.org Subject: Re: Jails and IP Aliasing X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 08 Jul 2008 17:02:08 -0000 Hello, > * Something like a loopback address inside the jail. It may be > 127.0.0.2 instead of 127.0.0.1 but most software can be persuaded > to use it for loopback style things. > > * The ability to map several IPs onto the jailed system by use of > NAT and redirect within firewall rules > > * The ability to have a jail with /no/ external IP for when the > paranoia becomes unbearable[*]. Most of this is actually implemented by bz@. You can find some patches at http://sources.zabbadoz.net/freebsd/jail.html -- Best regards, Daniel Gerzo