00:01:56 for a jail that doesn't have a public ip, and only has a private lan ip, i guess i don't set a default gateway address? 00:07:55 or do i make the jail host be the default gateway or? how do i know pls? 00:19:22 depends if the jail has its own network stack 00:32:27 ya it's vnet 00:33:58 on the host check, jls -N 00:34:10 and jexec nameofjail ifconfig 00:34:25 ok you're just telling me commands but WHY 00:34:28 like what's the point 00:35:12 it either shares the hosts network or has its own 00:35:28 i said it has vnet 00:37:06 my bad that you said vnet already, so the only thing left is what the jails epair is pluggeed into the host thats what decides the next hop 00:37:29 is your nic a physical member? 00:42:19 don't even know what your'e asking or why. i'm back at the conceptual stage. if a jail is only intended to have a private lan ip, it doesn't get a default gateway address configured right? 00:42:38 kinda rude for someone trying to help your vague question 00:43:09 agree to disagree 00:43:32 good luck 00:44:21 ya helping ppl usually involves actually reading their question and understanding what their goal is instead of just blurting shit out 00:44:56 ok, well you'll find what you're looking for eventully. need to remember that some people do this for a living. 00:44:57 later 00:50:35 for the record, public vs private has nothing to do with it. What matters is whether traffic actually leaves the subnet and pkg, dns, ntp all do so yes it gets a default gateway and since it's 'VNET' with its own routing table you set it in the jail ' defaultrouter="yourlanrouter", same address every other box on that lan uses. 00:51:15 the epair/bridge stuff i was asking about only matters if your setup isn't the simple bridged case. Which I was trying to establish... 00:53:57 jail uses host time so ntp is irrelevant afaik. pkg for the jail is also ran by the host. and there's no dns. this is all so that jails can be on a private lan, doing specific work in a service-oriented architecture, behind another jail that does have a public ip and proxies to the others on the private lan 00:58:43 yeah if the private jails only ever talk to the proxy jail on the same subnet then no default route needed at all. Now we know that nothing leaves the subnet. Also pkg -j runs pkg inside the jail, so with vnet it uses the jail network and dies with no route. use pkg -r /path/to/your/jail/ so the host fetches. If the proxy jail is on a diff subnet then the privat ones they do need a route back to it. static or default either way. 01:00:22 Oh, I need to think about that. I've set up NAT so I could reach out from my jails, but maybe I don't actually need it. 01:05:59 pkg -r 01:06:24 proxy jail has 2 epair nics. 1 with public ip and 1 with ip on private lan 01:07:06 mason ya i'm converting my jails to not need internet by default by using freebsd-update -j and pkg -r 01:07:31 nice nice 01:07:58 I've said this in here before, but my latest move is off of epair/vnet and onto old-fashioned networking for jails. I'm loving it. 01:09:00 I think the next move for me would have to be off of jails entirely and back to chroots. :P 01:09:03 why and how? 01:09:52 Why? Simplicity. How? I spin up a new lo interface for them to sit on, with a private subnet, and then just port forward in as needed, and NAT out, although clearly the NAT is optional. 01:10:35 ya that's cool. i'll still keep using vnet except for service jails that are just app containment but i see the value 02:17:16 so i got a jail host and vnet jail with no public ip, only private ip. i want to ssh to jail host port 555 and have it redirect to the jail's private ip and port 22. on jail host i made pf rule `rdr pass on pubif proto tcp from any to any port 555 -> 192.168.0.5 port 22` then it says blocking from bridge0 to 192.168.0.5, so i add pass on bridge, 02:17:17 reload pf, now i ssh to jail host port 555 but nothing happens. what i'm doing wrong pls? 02:30:51 i don't have a nat rule set maybe that's it? also don't have a default gateway set for jail 05:15:58 kerneldove: I'd personally just ssh with the host as a proxyjump. 05:18:31 personally I never use VNET jails unless there's a true need for it - feels overly-complicated. no epairs, no bridges, just an alias on the host and you can do that even if you have an int and ext network on two ports on your host. 05:20:07 it is complex, thats why you automate it so it becomes simple, but generally agreed. 05:20:17 working on automating it now 05:20:35 i want vnet for max security because i'm giving jails out to friends as virtual freebsd systems 05:21:02 Complexity as in many moving parts, more than anything. Fewer moving parts == good. 05:21:23 Anyway, g'night. 05:24:00 well i had a perfect configuration for jails that have their own public ip (and private ip) i'm switching now to not requiring jails to have a public ip so that requires quite a bit of chnages. i'll hammer on that and eventually get it solid too 05:26:52 my goal is to eventually take the 'anonssh' program I wrote and turn it into 'minijail', so you can launch any program in a jail and only include that programs dependencies. So much less than base. A single user, maybe root. It already works but is tighly coupled to launching sshd in a jail rather than any program. 05:38:21 is there any value in putting different groups of jails on different bridges? like to isolate jails from 1 user from jails of another user? 14:46:03 Are these the strongest GELI settings? geli init -e AES-XTS -l 256 -a HMAC/SHA512 -s 4k /dev/disk 14:51:24 yes 14:57:56 yay! 15:05:57 ForeverNoob[m]: pretty sure thats default though :p 15:06:15 also isn't AES-XTS vs AES-CBC still disputed? :p 15:07:30 XTS is for data at rest. CBC is for data in motion. 15:20:30 I will be holding a FOSS meetup in London on the 8th August, if you are interested please PM me for details! 15:20:39 I dont think there is any ML I can really put it on for freebsd 15:20:43 so the IRC will have to do 15:38:07 Would if I could! 15:38:29 Ugh, this is just _so_ annoying: https://forums.freebsd.org/threads/geom_eli-failed-to-authenticate.62401/ 15:39:23 Overwriting 4x 16TB drives with /dev/random is going to be a "fun" experiment in patience. 16:32:28 is there any value in putting different groups of jails on different bridges? like to isolate jails from 1 user from jails of another user? 16:35:09 thats not a jail issue, thats a network design issue 16:35:52 VNET jails for example would already have their own interface 16:39:26 dunno what any of that meant. the question is, put all jails for different people on the same bridge, or put jails for each person on their own bridge 16:41:47 https://freebsdfoundation.org/wp-content/uploads/2020/03/Jail-vnet-by-Examples.pdf 16:53:46 ? 18:23:10 ok got ssh into jail without public ip working using port forwarding 18:27:50 kerneldove: Might be simpler still to use ProxyJump. 18:29:09 kerneldove: Advantage: you're not exposing additional SSH ports. 18:29:51 That said, locking that down to just individual users and not letting them connect to the host itself or to other jails might be difficult. 18:43:07 well simpler isn't my #1 priority. dunno what proxyjump is but i got this working with just base fbsd functionality. pf, vnet jails, bridges 19:12:20 I am at a point where I am a hair distance from switching to FreeBSD in the future 19:12:41 I am noticing the political front in the linux community and it isn't for me. I like the non-woke distros but even they seem to be politica 19:12:47 I just refuse to participate in all of that 19:13:08 also I don't support Linus Torvalds woke agenda and his membership to the WEF 19:13:16 he is a globalist 19:13:21 I'm not for that either 19:13:32 I support Slackware's ideology 19:13:57 currently I am using Devuan but eventually Debian will sabotage that because they have the common liberal leftist globalist ideology 19:14:25 they will do it because it is their code base and Linus will put AI in the kernel like copilot and very soon Bill Gates and M$ will own linux 19:14:30 If you're going to be like this, openly, and unapologetically, to a significant subset of FreeBSD's users, just leave. Your behaviour does not appear conducive to the desired environment. 19:14:43 well I am saying this. FreeBSD is NOT linux 19:14:47 it is a separate OS 19:14:51 they are NOT the same thing 19:14:54 linux is a kernel 19:14:56 See points 2 and 3 of the topic's first section: be civilised, and respect others 19:14:58 FreeBSD is an OS 19:15:22 I will be civilized but I am not going to tolerate bullies of any type 19:15:25 that's just how it is 19:15:27 I don't have to 19:15:49 I don't see how praising "non-woke" and "anti-woke" is respecting others when "woke" is comprised of a single proposition: injustices can be combatted 19:16:17 seems rather unrelated to the OS either way... 19:16:35 well it is like this... I am not about politics. I am about what is actually true. I've spent the last 10 years doing research and I mean real research and not media research and not just believing things I am told. 19:16:41 I am not saying that everyone does this 19:16:48 I proffer that you're an agent-provocador from casa de Lunduke. 19:16:55 there are tons of people in Europe who are well aware and making the same decisions 19:17:09 yeah I dunno, if you like freebsd use it 19:17:11 no it isn't even that I support Lunduke. I think for myself 19:17:13 not a lemming 19:17:25 mewt, FreeBSD looks pretty good 19:17:27 but this is not really related to...well...the OS at all 19:17:32 lotta folks, mostly men, have told me that. 0% of them actually do think for themselves 19:17:33 it isn't 19:17:40 I thought I joined the offtopic chan 19:17:41 lol 19:17:45 anyway fair point 19:17:59 forewarned is forearmed, your behaviour is also not conducive to the desired enviroment over in -social 19:18:11 this and the "prove to me I should switch to your distro/OS" in what is nominally a support channel is tiring after a while 19:18:13 Reinhilde, I take your "forewarnings" as threats 19:18:45 Take them thus, if you like. I'm not here to implant a mode of thinking into you, you seem to have plenty of people like that for you already. 19:18:47 I am civil but once again not a serf 19:19:06 * Reinhilde ## A quiet "plonk" rings out in the distance. 19:20:20 the point I make is very simple. People want privacy, they want control over their OS, they want freedom with what they do with their OS and then they submit to the people who do not want them to have it. The entire thing is about money 19:20:26 it should be FOSS 19:20:28 not politics 19:20:56 I like FreeBSD's design and license so far from what I am seeing 19:21:22 I notice that its community is not about politics ( or shouldn't be because they are not the linux community ) 19:22:20 mewt, you don't have to prove to me why I should switch to FreeBSD. The behavior of many people are already doing that 19:23:56 I am enjoying Devuan but I see this as a temporary situation perhaps. It is a matter of time until that situation implodes on all debian based distros and I will be forced to either migrate to slackware, freebsd, or another bsd-like distro 19:24:18 *plonk: the sequel* 19:24:22 so anyway. I do apologize for this not being the offtopic channel and I will take note in the future 19:24:31 I will be leaving now as I am unwelcome even by the nonpolitical 19:26:17 unlike this nimrod, I am well aware of the fact that FOSS and communities around it are an explicitly political project. 19:26:27 (thankfully the nimrod left the channel.) 19:26:46 guess it really was just looking for reactions 19:27:37 it as in their behaviour I suppose? 19:28:42 yes 21:10:05 not very welcoming 21:21:02 It was very #freebsd-social 21:55:35 updating one of my ec2 instances from 15.0 to 15.1 and i'm at the step of updating the bootloader, however the freebsd-boot partition is only 16K and is not large enough for gptboot... any ideas? :/ 21:57:13 it seems to have booted just fine into 15.1-RELEASE so.. idunno, nothingburger? heh 22:06:03 wcarson: They're legacy then? 22:08:17 what do you mean by legacy? 22:35:56 * spork_css puts on off-topic hat 22:36:30 I find many people that speak at length about "doing their own research" end up being very Dunning-Kruger 22:36:58 spork_css: There's actual #freebsd-social for this, FWIW. I don't see you in there, but it's the Right Place. 22:37:09 I have more commentary for there if you join it. 22:37:29 just a throwback to our wanderer that left... 22:37:33 Yeah. 22:38:47 speaking of that, bouncers besides znc that people like, because this setup for an irc newb is both too GUI and not GUI enough, if that makes sense. 22:39:30 spork_css: Here, it's just irssi on a host that stays up and connected, and I ssh into it. 22:53:41 maybe I need to give myself a little shove with znc here and see if I can convince it to join -social with only sending commands to it via this irc app (Textual on macos, fork of LimeChat, FWIW). 22:55:48 Hm. ZNC has always seemed daunting here. 22:56:02 Maybe if you get it to work, you can write up what you did...? 22:58:07 spork_css: if you are connected to your znc from textual if you join a channel it should just save it and join next time as well 22:58:41 remember textual is actually connected to your znc and not just plain irc so what you send it, you send to znc 23:00:31 I've been configuring "join list on start" via znc, and thinking that's the only way to do it, but I just right-clicked on the Libera (via znc) network and there was a "list channels" - and I clicked -social and there I am. Man... 23:01:21 I setup znc years ago just for all the scrollback features plus the general urge to not connect directly from home and just never dug in to it. 23:02:27 mines setup to just pull up everything on my znc, but i've not changed a conf manually in over a decade by now, i'd have to re-learn it all to change anything 23:04:21 I've taken to leaving keywords in files I search (really a database, but...) for things I do periodically and forget. So I document them and then search as needed. Some of this makes it onto various wikis.