Re: Jail isolation from internal network and host (pf, vnet (vimage), freebsd 11.1)

2017-11-08 Thread Sami Halabi
Hi, To completly isolate specific jail come to my mind the following solution: 1. use vimage. 2. setup 1 broker jail - that jail will have ipfw (or pf if but i recall it have several bugs and kerbel panics ) with nat, will have 2 nics of 2 different epairs, one to the host and other to the isolated

Re: Upgrading FreeBSD to use the NEW pf syntax.

2012-11-20 Thread Sami Halabi
tion about this, > but i do not know how keen they are to support through funding this. > > When the locking was changed there were a discussion about keeping both of > the versions but it was just thrown to the trash by the guy doing > the new 'locking'. &g

Re: VNET

2012-06-20 Thread Sami Halabi
bsd.org> wrote: > On 19.06.2012 12:56, Sami Halabi wrote: > >> Hi, >> >> I want to ask aout VNET jails, i read somehwre that I'm able to run IPFW, >> but not PF firewall in a cnet jail. >> is that correct? >> >> i want a vnet jail basicly for

VNET

2012-06-19 Thread Sami Halabi
here... Thanks in advance, -- Sami Halabi Information Systems Engineer NMS Projects Expert FreeBSD SysAdmin Expert ___ freebsd-pf@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-pf To unsubscribe, send any mail to "freebsd-p