Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-31 Thread carlopmart
On 10/31/2011 01:32 PM, Jeppe Toustrup wrote: On Sun, Oct 30, 2011 at 22:59, carlopmart wrote: Many thanks Jeppe. I am reconfiguring this zone to use ip-type=shared instead of exlusive. My zone config is: ... But when I try to boot this new zone, console returns me this error: "WARNING: skip

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-31 Thread Jeppe Toustrup
On Sun, Oct 30, 2011 at 22:59, carlopmart wrote: > Many thanks Jeppe. I am reconfiguring this zone to use ip-type=shared > instead of exlusive. My zone config is: > > ... > > But when I try to boot this new zone, console returns me this error: > > "WARNING: skipping network interface 'e1000g1' whi

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread carlopmart
On 10/30/2011 12:29 PM, Jeppe Toustrup wrote: On Sun, Oct 30, 2011 at 09:27, carlopmart wrote: Thanks Jeppe. I don't have configured a etherstub. current config is: root@oihost:~# dladm show-vnic LINK OVER SPEED MACADDRESSMACADDRTYPE VID dmzlan0 e1000g1

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread Josef 'Jeff' Sipek
On Sun, Oct 30, 2011 at 10:24:33AM +0100, carlopmart wrote: > I will try to explain something more. I need to build a complete > public dmz infrastructure using oi zones (if I can). OIhost is on > internal network without Internet access. On this host I have three > physical nics: > > a) e1000g0 -

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread Jeppe Toustrup
On Sun, Oct 30, 2011 at 09:27, carlopmart wrote: > Thanks Jeppe. I don't have configured a etherstub. current config is: > > root@oihost:~# dladm show-vnic > LINK         OVER         SPEED  MACADDRESS        MACADDRTYPE         VID > dmzlan0      e1000g1      1000   2:8:20:dc:48:d9   random      

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread carlopmart
On 10/30/2011 09:53 AM, carlopmart wrote: On 10/30/2011 09:27 AM, carlopmart wrote: On 10/30/2011 02:27 AM, Jeppe Toustrup wrote: On Sat, Oct 29, 2011 at 23:30, carlopmart wrote: I have installed oi zone under a oi_151a host to provide dns caching services. All works ok now, except network iso

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread carlopmart
On 10/30/2011 09:27 AM, carlopmart wrote: On 10/30/2011 02:27 AM, Jeppe Toustrup wrote: On Sat, Oct 29, 2011 at 23:30, carlopmart wrote: I have installed oi zone under a oi_151a host to provide dns caching services. All works ok now, except network isolation. Running snoop on non-global zone I

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-30 Thread carlopmart
On 10/30/2011 02:27 AM, Jeppe Toustrup wrote: On Sat, Oct 29, 2011 at 23:30, carlopmart wrote: I have installed oi zone under a oi_151a host to provide dns caching services. All works ok now, except network isolation. Running snoop on non-global zone I can see all traffic of all networks wher

Re: [OpenIndiana-discuss] Isolating networks for zones

2011-10-29 Thread Jeppe Toustrup
On Sat, Oct 29, 2011 at 23:30, carlopmart wrote: >  I have installed oi zone under a oi_151a host to provide dns caching > services. All works ok now, except network isolation. Running snoop on > non-global zone I can see all traffic of all networks where global zone > connects. For example: How

[OpenIndiana-discuss] Isolating networks for zones

2011-10-29 Thread carlopmart
Hi all, I have installed oi zone under a oi_151a host to provide dns caching services. All works ok now, except network isolation. Running snoop on non-global zone I can see all traffic of all networks where global zone connects. For example: root@oizone01:~# snoop -r Using device dmzlan0 (