Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 2 Nov 2017 13:19:31 +0100
From:      Marko =?UTF-8?B?Q3VwYcSH?= <marko.cupac@mimar.rs>
To:        freebsd-net@freebsd.org
Subject:   Re: VLANing between jails not segmenting traffic
Message-ID:  <20171102131931.452f1106@efreet-freebsd.kappastar.com>
In-Reply-To: <2A44422B-31A9-4ADC-8FCE-D1F8BC03623C@freebsd.org>
References:  <4d50ef1e-1cc2-aca2-d390-313ef824d524@gmail.com> <59F79902.40408@grosbein.net> <2A44422B-31A9-4ADC-8FCE-D1F8BC03623C@freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, 30 Oct 2017 22:46:35 +0100
Michael Gmelin <grembo@freebsd.org> wrote:

> You can use fibs with net.add_addr_allfibs=3D0 to get separate routing
> tables (comes with its own set of complications though).

I hoped to go this way, but the fact that host (in fib0) replies to
icmp requests destined to jail with raw_sockets disabled (in fib 1) via
host's default gateway, making really wierd routing situation.

Had to go back to separate physical hosts for now. Will check VIMAGE.
--=20
Before enlightenment - chop wood, draw water.
After  enlightenment - chop wood, draw water.

Marko Cupa=C4=87
https://www.mimar.rs/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20171102131931.452f1106>