net.inet.ip.fw.verbose in jails

"Patrick M. Hausen" <[email protected]>
Newsgroups gmane.os.freebsd.devel.net
Message-ID <[email protected]>
Hi all,

one customer started to make more use of IPFW inside
their vnet jails in our hosting environment.

When they

-	create a firewall rule with "log" set, like:
	ipfw add 65532 allow log ip from me to any out
-	set:
	sysctl net.inet.ip.fw.verbose=1

all *inside* a jail, the firewall rules work as expected, yet
the log entries end up in /var/log/security on the host.

All the time net.inet.ip.fw.verbose on the host is set to 0.

Is this intentional? Or fundamental, because there is only
a shared host kernel with jails?

Or is it a bug?

I checked multiple times, the sysctl variables can be set for
each jail and the host independently just like each can have
its own set of firewall rules.

Kind regards,
Patrick
-- 
punkt.de GmbH
Patrick M. Hausen
.infrastructure

Sophienstr. 187
76185 Karlsruhe

Tel. +49 721 9109500

https://infrastructure.punkt.de
[email protected]

AG Mannheim 108285
Geschäftsführer: Daniel Lienert, Fabian Stein
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.