Re: deploy multiple vnets with VIMAGE/VNET + Production Ready?

2016-05-30 Thread Lars Engels
On Mon, May 30, 2016 at 09:40:42AM -0400, Ernie Luzar wrote: > Here are the bare truths without any sugar coating. > Vimage is officially described as experimental. You have to recompile > the kernel to included vimage. Enabling pf or ipf firewalls cause the > host to crash. ipfw firewall does no

Re: deploy multiple vnets with VIMAGE/VNET + Production Ready?

2016-05-30 Thread Sebastián Maruca via freebsd-jail
I thank you all for your fast and kind reply! I was in spite of building some kind of API above pf(4) to let each jail act as a tenant firewall... Maybe I should wait to 11-RELEASE birth to go for it...  Meanwhile I think I'll get over it with an API/framework that can handle pf with its anchor f

Re: deploy multiple vnets with VIMAGE/VNET + Production Ready?

2016-05-30 Thread wishmaster
Hi, > Hi to everyone! > I want to deploy several "jailed" firewalls, where each one of them would > contain at least three multiple virtual interfaces (associated with virtual > internal nets) like "WAN", "LAN" and "DMZ" for example... > First *innocent* question (I beg you pardon for my ignora

Re: deploy multiple vnets with VIMAGE/VNET + Production Ready?

2016-05-30 Thread Ernie Luzar
Here are the bare truths without any sugar coating. Vimage is officially described as experimental. You have to recompile the kernel to included vimage. Enabling pf or ipf firewalls cause the host to crash. ipfw firewall does not cause a crash but has next to no real life usage on vimage. When