-
Notifications
You must be signed in to change notification settings - Fork 556
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Change iptables rules #403
Comments
Use --join-network. It is very flexible, you can do much more than changing netfilter, you can also change IP addresses, add interfaces etc. Example:
|
It works, thanks! But there's something weird. I tried
and |
First you might want to verify if those settings are still active by running Did you try ifconfig inside the jail or on the host? And the address, is it an address that starts with What do you mean with "protocol doesn't contain To answer your question of "does it mean you have an IPv6 connection in any way" the honest answer is yes, at least partially, iff both endpoints have that fe80 address. I'll briefly try to explain. What I mean is, the |
I've just checked and
I never use Since I use |
I still have to look into it. I think that net.ipv6.conf entries are per-namespace. It could be possible to totally disable ipv6 or ipv4 as requested in --protocol command. |
@nick75e Is this still an issue? |
yes, I still get an IPv6 address. |
Hmm, this is definitely not ideal. Inside the jail ( |
Some sysctl settings are per network namespace, |
iptables
rules can only be set when starting a sandbox.Is it possible to have an option to load a different config file while a sandbox is running.
Thanks.
The text was updated successfully, but these errors were encountered: