Date: Sun, 25 May 2008 22:47:55 +0100 From: "Steven Hartland" <killing@multiplay.co.uk> To: "Geoffroy DESVERNAY" <dgeo@ec-marseille.fr>, <freebsd-jail@freebsd.org> Subject: Re: Jail resource limits Message-ID: <1F08E6231F60497A9BF556590BB56E9A@multiplay.co.uk> References: <822C1BB6-3591-4CE1-AFEA-8B07B9F5ED8D@pean.org><483556DB.9070602@quip.cz><08244555-5BD2-4F67-B311-CCC5E316A068@pean.org> <20080522165219.D47338@maildrop.int.zabbadoz.net> <8068148B75CB4B3E953144A0DF47E496@multiplay.co.uk> <4839CEFC.1050605@ec-marseille.fr>
next in thread | previous in thread | raw e-mail | index | archive | help
----- Original Message ----- From: "Geoffroy DESVERNAY" <dgeo@ec-marseille.fr> >> This is something we're really looking forward to tbh a great >> feature :) One of the reasons for this is hosting jails, with >> the addition of multi IP support we will be able to enable >> jails to connect to "backdoor" secure services such as a >> mysql server. >> > We are already doing this (sql on a separated(physical) LAN, but jail > don't need a second interface for that: the real host's routing table is > used for outgoing packets. > Note we still need a static route on the SQL server for the packets to > come back the same way > > I still don't know if this behaviour is the better one (one may think > that jail's packets should not go through different interface ?), but it > works quite well ;) Surely that compromises jail security i.e. being able to access resources from the host box even it the jail has no perceivable access to them? I assume this still doesn't work if the server is in fact run on the main host only running on localhost? Regards Steve ================================================ This e.mail is private and confidential between Multiplay (UK) Ltd. and the person or entity to whom it is addressed. In the event of misdirection, the recipient is prohibited from using, copying, printing or otherwise disseminating it or any information contained in it. In the event of misdirection, illegible or incomplete transmission please telephone +44 845 868 1337 or return the E.mail to postmaster@multiplay.co.uk.
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1F08E6231F60497A9BF556590BB56E9A>