"ipfw log" messages from jail show in host syslog

Kristof Provost kp at freebsd.org
Tue Feb 12 08:35:12 UTC 2019


On 2019-02-11 22:37:07 (-0800), Rudy (bulk address) <crapsh at monkeybrains.net> wrote:
> I've switched to VNET (love it) in jails.  Neat, you an have ipfw running
> in your jail!
> 
> I added some log lines to test it out and was a bit confused when
> /var/log/security wasn't showing the log lines.  Turns out, the kernel is
> grabbing them and logging in the host and not the chrooted environment.
> 
> Bug?  Feature?  :)
> 
"Known limitation", I think[*].

>From a quick look at the ipfw log code it appears to simply write the
logging information to the kernel log, which is not a per-jail things.

I don't expect this to be easy to change either.

Regards,
Kristof

[*] Not an ipfw maintainer. Warranty void where prohibited. Do not feed
after midnight.


More information about the freebsd-jail mailing list