From owner-freebsd-jail@FreeBSD.ORG Mon Jun 9 19:36:22 2008 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 1CC11106566B for ; Mon, 9 Jun 2008 19:36:22 +0000 (UTC) (envelope-from nbari@k9.cx) Received: from an-out-0708.google.com (an-out-0708.google.com [209.85.132.247]) by mx1.freebsd.org (Postfix) with ESMTP id D65758FC16 for ; Mon, 9 Jun 2008 19:36:21 +0000 (UTC) (envelope-from nbari@k9.cx) Received: by an-out-0708.google.com with SMTP id b33so556303ana.13 for ; Mon, 09 Jun 2008 12:36:21 -0700 (PDT) Received: by 10.100.202.9 with SMTP id z9mr4294181anf.8.1213040178225; Mon, 09 Jun 2008 12:36:18 -0700 (PDT) Received: from ?192.168.1.10? ( [148.244.166.166]) by mx.google.com with ESMTPS id a38sm310092rnc.4.2008.06.09.12.36.16 (version=TLSv1/SSLv3 cipher=RC4-MD5); Mon, 09 Jun 2008 12:36:17 -0700 (PDT) Message-Id: <10EDE3B1-4574-4EEA-B913-AE72AF89DCD0@k9.cx> From: Nicolas de Bari Embriz Garcia Rojas To: Bjoern A. Zeeb In-Reply-To: <20080609173344.O83875@maildrop.int.zabbadoz.net> Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit Mime-Version: 1.0 (Apple Message framework v924) Date: Mon, 9 Jun 2008 14:36:13 -0500 References: <4F5A1DE6-3E56-4F53-9C0F-90D318DF8AC7@k9.cx> <20080609173344.O83875@maildrop.int.zabbadoz.net> X-Mailer: Apple Mail (2.924) Cc: freebsd-jail@freebsd.org Subject: Re: ipsec X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 09 Jun 2008 19:36:22 -0000 Hello, how to use the correct policy on the base host ? can you please explain more. regards. -- > nbari On Jun 9, 2008, at 12:34 PM, Bjoern A. Zeeb wrote: > On Fri, 6 Jun 2008, Nicolas de Bari Embriz Garcia Rojas wrote: > >> I had to make an VPN using IPSEC, the vpn is on the master host and >> is working but if it is only available from the master host not the >> jails, how can i make the jails to ping/access/telnet the VPN? > > use a correct policy on the base host (you cannot do this from within > the jail). > > > PS: things like this are better discussed on net@ > > -- > Bjoern A. Zeeb Stop bit received. Insert coin for new > game.