Re: net.inet.ip.fw.verbose in jails

Lee Brown <[email protected]>
Newsgroups gmane.os.freebsd.devel.net
Message-ID <CAFPNf5_+dQjxGc1VVmZ_YVv_UC5JG0wBaowu=3oaQKNS2S09kg@mail.gmail.com>
I've had that happen if the jails don't have syslogd running inside them.

On Fri, Jul 18, 2025 at 6:25 AM Patrick M. Hausen <[email protected]> wrote:

> Hi all,
>
> one customer started to make more use of IPFW inside
> their vnet jails in our hosting environment.
>
> When they
>
> -       create a firewall rule with "log" set, like:
>         ipfw add 65532 allow log ip from me to any out
> -       set:
>         sysctl net.inet.ip.fw.verbose=1
>
> all *inside* a jail, the firewall rules work as expected, yet
> the log entries end up in /var/log/security on the host.
>
> All the time net.inet.ip.fw.verbose on the host is set to 0.
>
> Is this intentional? Or fundamental, because there is only
> a shared host kernel with jails?
>
> Or is it a bug?
>
> I checked multiple times, the sysctl variables can be set for
> each jail and the host independently just like each can have
> its own set of firewall rules.
>
> Kind regards,
> Patrick
> --
> punkt.de GmbH
> Patrick M. Hausen
> .infrastructure
>
> Sophienstr. 187
> 76185 Karlsruhe
>
> Tel. +49 721 9109500
>
> https://infrastructure.punkt.de
> [email protected]
>
> AG Mannheim 108285
> Geschäftsführer: Daniel Lienert, Fabian Stein
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.