[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [ezjail] Two jail newbie questions



On Tue, 23 Oct 2007, Alex Moura wrote:
:> > I have installed the jail system using ezjail and it is up and running.
:> >...
:>
:> > Q. 1.
:> > Inside the jail I cannot ping out.
:> this is intended. jail(8) prevents use of raw sockets.
:
:But this can be override by this line in /etc/rc.conf
:
:jail_socket_unixiproute_only="NO"
:
:Whithout rebooting, can be set manually by root:
:
:sysctl security.jail.socket_unixiproute_only=0

Thanks, I didnt realize that users/services inside the jail couldnt 
initiate connections outside the jail, but 
after thinking about it, it make perfect sense. 

:> > From outside the jail I cannot ssh in.
:> > Where should I look at to fix this.  sshd is running inside the jail.
:> > I get the error
:> > ssh: connect to host xxx.65.222.198 port 22: No route to host
:> i cannot reproduce this with my setup. but i remember problems last time i
:> tried to abuse the loopback if for jails.

This wound up being caused by my not having set up sshd properly.  Once I 
went back through and ran ssh-keygen for the key sets everything worked 
properly. 


:Check which IP/port the ssh process is listening to with:
:
:sockstat -l4
:
:> > Should I set the jail IP on the nve0 interface instead of the lo0
:> > interface?
:> it is one solution. another one would be to create a special purpose jail
:> interface (ifconfig lo1 create; ifconfig lo1 name jail1; ifconfig jail1 inet xxx.65.222.198/32)
:
:The easy way would be setting the jail ip as a secondary IP address to
:nve0, by using the ifconfig alias parameter.

I used nve0 to get the jail access working.  I tried using the loopback address  
but couldnt figure out how to obtain connectivity to the jail with it. 

:> > Q. 2.
:> > I also tried to add some software from ports as root inside the jail
:> > but cannot access the ports tree.
:>
:> you did install a ports tree inside the jail (ezjail-admin -p) ?
:
:And update it later by using
:
:ezjail-admin update -P

:NOTE: The -p and -P parameters are not the same.

I had thought that the ports were installed by default. Not sure why I had 
thought that but now I know.


Thanks for you response Alex, being new to jails any and all help is 
appreciated.

rick