EZJAIL and ping on FreeBSD-11.

James B. Byrne byrnejb at harte-lyne.ca
Thu Feb 1 15:23:18 UTC 2018

I have read the various 'howtos' respecting this issue and I cannot
see where I have failed to properly follow the instructions. But
clearly I have not done it right.

I have setup a jail named hll124.  it is configured and running.  It
can connect to the network and the Internet without issue. DNS
resolution works fine using local_unbound.

In /etc/sysctl.conf on the host I have this:

# Uncomment this to prevent users from seeing information about
processes that
# are being run under another UID.

# Required for Chrome/Chromium

# Add to allow jails to create sockets - 2018-01-31 JBB

The host system shows this:

$ sudo sysctl security.jail.allow_raw_sockets
security.jail.allow_raw_sockets: 1

In the ezjail configuration file I have this:

# Allow ping, traceroute and other things 2018-01-31 JBB
export jail_hll124_allow_raw_sockets="YES"

When I connect to the ezjail instance with ezjail-admin console and
run ping then I see this:

# ping
ping: ssend socket: Operation not permitted

What else am I missing?

