From nobody Sat Jul 24 11:38:16 2021 X-Original-To: freebsd-jail@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id B9B3A12B3207 for ; Sat, 24 Jul 2021 11:38:22 +0000 (UTC) (envelope-from jacques+freebsd@foucry.net) Received: from mail.foucry.net (fournil.foucry.net [95.217.83.231]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4GX4263qZLz4YYb for ; Sat, 24 Jul 2021 11:38:21 +0000 (UTC) (envelope-from jacques+freebsd@foucry.net) Received: from mail.foucry.net (unknown [192.168.12.17]) by mail.foucry.net (Postfix) with ESMTP id D8B80FA02 for ; Sat, 24 Jul 2021 11:38:19 +0000 (UTC) X-Virus-Scanned: amavisd-new at foucry.net Received: from mail.foucry.net ([192.168.12.17]) by mail.foucry.net (mail.foucry.net [192.168.12.17]) (amavisd-new, port 10024) with ESMTP id GXS8471CiCAH for ; Sat, 24 Jul 2021 11:38:19 +0000 (UTC) Received: by mail.foucry.net (Postfix, from userid 58) id 68F26FA01; Sat, 24 Jul 2021 11:38:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=foucry.net; s=dkim; t=1627126699; bh=XUAW2nSKNlYM2KlLNo26SM2+LEBDoxhzoC0/PF6mw9U=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=QcUnhN35i552Db/K+krBn7AHdRJ8dQ+I6FdqZFudi/vb1WkAgrx7GiccRrFbsYjNi ge4oz9fhA/o6KN1HEq6KfTjFaG2CYYKBpMAXQsDFrARRsF+splAbBSp/DGHDXbJdBg 5Y46tUntwB2hwNI0i1RSMFPFdOa2mySm/kLGE+5Q= Received: from mithril.foucry.net (unknown [IPv6:2a01:e0a:434:44e0:ea6a:64ff:fe07:95a1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.foucry.net (Postfix) with ESMTPSA id 91483F4EB; Sat, 24 Jul 2021 11:38:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=foucry.net; s=dkim; t=1627126698; bh=XUAW2nSKNlYM2KlLNo26SM2+LEBDoxhzoC0/PF6mw9U=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=mC4tnMHi6SQoOXlSXdQpDL2Ty11Ul5ZunCRiYluoFZLPdoFhwASX7wueA1JQr3JAN UfvIA2iNUhAS0rmDzfklrUPiH6T0bBfL5XdU+hL9ljr9PcvDpcWfHRN7zl8Dg2nKA6 QcGyvk89V+2uj8HDwivau9RXymxNvT48GTme9gL0= Received: from mithril.foucry.net (localhost [IPv6:::1]) by mithril.foucry.net (Postfix) with ESMTPS id 778BE115B; Sat, 24 Jul 2021 13:38:17 +0200 (CEST) Date: Sat, 24 Jul 2021 13:38:16 +0200 From: Jacques Foucry To: infoomatic Cc: freebsd-jail@freebsd.org Subject: Re: iocage, vnet jail does not go outside Message-ID: Mail-Followup-To: infoomatic , freebsd-jail@freebsd.org References: <40b7782d-9d5c-099a-ed58-4476b3523d7a@gmx.at> List-Id: Discussion about FreeBSD jail(8) List-Archive: https://lists.freebsd.org/archives/freebsd-jail List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-jail@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <40b7782d-9d5c-099a-ed58-4476b3523d7a@gmx.at> X-Operating-System: FreeBSD X-Rspamd-Queue-Id: 4GX4263qZLz4YYb X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[freebsd] X-ThisMailContainsUnwantedMimeParts: N Le vendredi 23 juil. 2021 à 23:06:41 (+0200), infoomatic à écrit: Hello Robert, Thanks for your answer. > iocage autoatically creates a bridge with your physical interface and > the vnet interface. Imho this is wrong behaviour so I quit using iocage, > however, there is a workaround, for more info see [1] I read carfully the issue your pointed and it appears that the vnet_default_interface parameter set to auto, em0 is added to the bridge, set to none, em0 is not added to the bridge. So I stopped my jail, destroy bridge0 interface, set vnet_default_interface to none and restart the jail. As exepected em0 is not in the bridge any more: bridge0: flags=8843 metric 0 mtu 1500 description: jails-bridge ether 58:9c:fc:10:ed:66 inet 10.0.10.1 netmask 0xffffff00 broadcast 10.0.10.255 id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15 maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200 root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0 member: vnet0.657 flags=143 ifmaxaddr 0 port 6 priority 128 path cost 2000 groups: bridge nd6 options=9 Since from the jail I cannot ping anything, from outside I cannot connect to the jail and from the jail I cannot connect to outside host. In fact, see quickly, the situation is worst. I did not look at the routing tables yet (too many other things to do). As I understood your did not use iocage any more. Did you use the "raw" method (ie /etc/jail.conf)? If yes, I am really interested of "picture" of your configurætion. To be honest, I used to try the "raw" method whithout success before tring iocage. Thanks for your time and advices. -- Jacques Foucry