-
Notifications
You must be signed in to change notification settings - Fork 557
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is there a recommended workaround for using wlan interfaces with firejail? #1600
Labels
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
Comments
netblue30
added
the
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
label
Oct 11, 2017
Try this setup: https://firejail.wordpress.com/documentation-2/basic-usage/#routed You would need to configure a bridge device and start the sandboxes on that bridge. You will also need to set iptables on the main system to do network address translation between the bridge and your wlan interface. I think if you change eth0 with wlan0 in that script it will work. |
Thanks - I'll try that. |
Closed
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
Hi, many thanks for making this software available, it's an extremely useful tool!
I have been using
firejail
for a while now on my desktop machine withfirefox
,thunderbird
etc. each running in its ownxephyr
X11 sandbox, with--net=eth0
. Since this type of setup provides a good security boost to probably the most vulnerable components on most people's systems, I'd like to add instructions for using it to my EFI Install Guide on the Gentoo wiki.However, I understand from the
firejail
manpage that the--net=
option is incompatible with wlan interfaces. Since many users of my guide install to laptops with only WiFi, no Ethernet, my question is this: is there a recommended workaround for these cases? For example, can atun
interface be used infirejail
, with packets being forwarded to the wlan viaiptables
rules, or something similar?The text was updated successfully, but these errors were encountered: