Re: net.inet.ip.fw.verbose in jails
Lee Brown <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.net |
|---|---|
| Message-ID | <CAFPNf5_+dQjxGc1VVmZ_YVv_UC5JG0wBaowu=3oaQKNS2S09kg@mail.gmail.com> |
I've had that happen if the jails don't have syslogd running inside them. On Fri, Jul 18, 2025 at 6:25 AM Patrick M. Hausen <[email protected]> wrote: > Hi all, > > one customer started to make more use of IPFW inside > their vnet jails in our hosting environment. > > When they > > - create a firewall rule with "log" set, like: > ipfw add 65532 allow log ip from me to any out > - set: > sysctl net.inet.ip.fw.verbose=1 > > all *inside* a jail, the firewall rules work as expected, yet > the log entries end up in /var/log/security on the host. > > All the time net.inet.ip.fw.verbose on the host is set to 0. > > Is this intentional? Or fundamental, because there is only > a shared host kernel with jails? > > Or is it a bug? > > I checked multiple times, the sysctl variables can be set for > each jail and the host independently just like each can have > its own set of firewall rules. > > Kind regards, > Patrick > -- > punkt.de GmbH > Patrick M. Hausen > .infrastructure > > Sophienstr. 187 > 76185 Karlsruhe > > Tel. +49 721 9109500 > > https://infrastructure.punkt.de > [email protected] > > AG Mannheim 108285 > Geschäftsführer: Daniel Lienert, Fabian Stein > >