Re: New Config of Jails & 4 port NIC with 6.2 stable



On 2007-Apr-19 19:24:37 -0700, webmaster@xxxxxxxxxxxxxx wrote:
A FreeBSD Grasshopper needs help.

This is probably more -questions fodder but anyway...

like to configure the above with Jails
My aim is local DNS, DHCP, Apache1.3, MySQL 4, PHP4, etc, etc.
basic server stuff.

Whilst you need an IP address for a jail, you don't need to dedicate
an interface to a jail. Typically, you would create a number of
aliases on one interface and assign them to jails. If you have lots
of public addresses then you could use aliases on your public NIC.
Alternatively, you can create aliases on lo0 and use firewall software
(ipfw, IPfilter or pf) to redirect packets to the appropriate alias.

If you really need distinct physical interfaces, you could use an
IEEE 802.1Q VLAN trunk into your FreeBSD box and break it out into
as many vlan interfaces as you want.

--
Peter Jeremy

Attachment: pgp7TaghRYC28.pgp
Description: PGP signature



Relevant Pages

  • Re: jailed "system" needs IPV4 access
    ... >> I made a jail for a domain I host, according to the man page for jail. ... > Is it bound to a public IP on a real interface, ... > All my jails typically run on aliases off the loopback interface, ... The host has one real hardware network interface. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: jails and multple interfaces
    ... The server has two network interfaces, I am configuring one for host ... the jail servers. ... IP on the first interface. ... I want to segregate the jail and jail host traffic on separate interfaces. ...
    (freebsd-stable)
  • [ronvdaal@zarathustra.linux666.com: Possible security issue with FreeBSD 5.4 jailing and BPF]
    ... While playing around with FreeBSD 5.4 and jailing I discovered that it was ... and a BPF device is available in the jail ... "The Berkeley Packet Filter provides a raw interface to data link layers ... Now starting tcpdump in the jail: ...
    (FreeBSD-Security)
  • Re: different default gateway for jails planed/possible?
    ... > Now the DMZ is useless since anybody who broke into one jail can reach all ... > traffic on the router since the packets go straight to the GbE interface. ...
    (freebsd-current)
  • 5.5-stable network interface rl0 stops working
    ... interface on the maschine, rl1 is for backups/internal use only) stops ... traffic for the services in that specific jail. ... <ACPI PCI bus> on pcib0 ... on miibus0 ...
    (freebsd-stable)