Is there any guide how to set up jails (iocage) with vnet (I want to pf filter jails access to internal network)?
This is really starting to frustrate me, I am desperately trying to filter traffic from jails to internal network and wasted a few weeks worth of work in last 3 releases to no success. I have turned around all the freaking tutorials that exist on internet, to no success and in each release some different problems =/
Release 12, took iocage tutorial (bridge, vnets), jails can't connect anywhere =/
I have checked the kernel configuration and VIMAGE is compiled in by default. One of the things that I have disabled (well as much as I could without recompiling kernel) is IPV6 as it is a complete overhead of administration for home network, but I doubt this could be the reason.
In jail ping -S <jail ip> <gateway> doesn't work and returns "ping: bind: Can't assign requested address" which is somehow strange (raw sockets are enabled).
Routing table seems fine.
I am not clueless about networking but this one is wearing me down, I have capitulated two times already and not using jails as they are completely useless to me, if there is no way to DMZ them.
This is really starting to frustrate me, I am desperately trying to filter traffic from jails to internal network and wasted a few weeks worth of work in last 3 releases to no success. I have turned around all the freaking tutorials that exist on internet, to no success and in each release some different problems =/
Release 12, took iocage tutorial (bridge, vnets), jails can't connect anywhere =/
I have checked the kernel configuration and VIMAGE is compiled in by default. One of the things that I have disabled (well as much as I could without recompiling kernel) is IPV6 as it is a complete overhead of administration for home network, but I doubt this could be the reason.
In jail ping -S <jail ip> <gateway> doesn't work and returns "ping: bind: Can't assign requested address" which is somehow strange (raw sockets are enabled).
Routing table seems fine.
I am not clueless about networking but this one is wearing me down, I have capitulated two times already and not using jails as they are completely useless to me, if there is no way to DMZ them.
Code:
cloned_interfaces="bridge1"
ifconfig_bridge1="addm re0 up"
Code:
net.inet.ip.forwarding=1 # Enable IP forwarding between interfaces
net.link.bridge.pfil_onlyip=0 # Only pass IP packets when pfil is enabled
net.link.bridge.pfil_bridge=0 # Packet filter on the bridge interface
net.link.bridge.pfil_member=0 # Packet filter on the member interface
Code:
"defaultrouter": "192.168.1.1",
"interfaces": "vnet1:bridge1",
"ip4_addr": "vnet1|192.168.1.21/24",
Last edited by a moderator: