Page 1 of 1
No internet connectivity inside of jail
Posted: 26 May 2014 16:29
by veganzombie
I've been trying to setup a jail within the brig for most of the day and I'm having a difficult time. I got everything working in a virtual machine just fine. I even got plex to work! But when it was time to get Plex installed on my live NAS it failed.
I created the jail within the same subdomain as the gateway. It is outside of DHCP range on an unused IP. I enable ping using the additional options field in the jail settings and I can ping anywhere inside of my network. I can ping the gateway and the gateway can ping the jail, etc. But I always time out when I try to ping an outside IP address. I have tried reinstalling the brig and recreating the jails multiple times, I tried adding the interface to rc.conf manually and even multiple DNS entries in the WebGUI for NAS4Free. The nameservers look fine as well and the default gateway seems correct when I run netstat.
I'm out of ideas but I feel like it's a tiny little detail that I'm missing. I'm hoping somebody can help me out.
Here's the ifconfig outside of the jail:
Code: Select all
re0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=8009b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,LINKSTATE>
ether 00:24:1d:c3:b5:d8
inet 172.16.100.2 netmask 0xffffff00 broadcast 172.16.100.255
inet 172.16.100.11 netmask 0xffffff00 broadcast 172.16.100.255
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
ipfw0: flags=8801<UP,SIMPLEX,MULTICAST> metric 0 mtu 65536
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
options=600003<RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6>
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0xa
inet 127.0.0.1 netmask 0xff000000
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
And inside the jail:
Code: Select all
re0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=8009b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,LINKSTATE>
ether 00:24:1d:c3:b5:d8
inet 172.16.100.11 netmask 0xffffff00 broadcast 172.16.100.255
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
ipfw0: flags=8801<UP,SIMPLEX,MULTICAST> metric 0 mtu 65536
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
options=600003<RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6>
Re: No internet connectivity inside of jail
Posted: 26 May 2014 16:57
by fumantsu
you have try nslookup 8.8.8.8?
Re: No internet connectivity inside of jail
Posted: 26 May 2014 17:04
by dreamcat4
You can install the CLI tool "finch", which isn't related to theBrig.
http://dreamcat4.github.io/finch/jails-how-to/
I support Finch myself, and will offer help and support for it.
Re: No internet connectivity inside of jail
Posted: 26 May 2014 18:07
by veganzombie
nslookup 8.8.8.8 times out when I run it.
I could try Finch but I liked the idea of having a GUI to manage the system. i may resort to it if I can't get this jail working in a little while.
Re: No internet connectivity inside of jail
Posted: 04 Jun 2014 03:52
by chachi420
Can you send me a screenshot of your "system" > "General" page as well as "Network" > "LAN Management" page?
Re: No internet connectivity inside of jail
Posted: 20 Jun 2014 21:32
by Chakalov
I'm having the exact same issue.
I personally have a perfectly working Nas4free storage at home with a Jail for a Plex server. Internet is flowing in and out with no problem at all. After a while a friend of mine asked me to make him a NAS for a small office of his and also if I could bring him OwnCloud functionality as well. I've created the Jail but there seems to be an issue with the internet connection... The NAS has a static IP set from the router and despite the Jail everything is working properly. Here are the "system" > "General" page as well as "Network" > "LAN Management" pages:
I would highly appreciate any kind of help that could stop me from pulling my hair already!
Thank you in advance!
Re: No internet connectivity inside of jail
Posted: 20 Jun 2014 22:24
by chachi420
Chakalov wrote:I'm having the exact same issue.
I personally have a perfectly working Nas4free storage at home with a Jail for a Plex server. Internet is flowing in and out with no problem at all. After a while a friend of mine asked me to make him a NAS for a small office of his and also if I could bring him OwnCloud functionality as well. I've created the Jail but there seems to be an issue with the internet connection... The NAS has a static IP set from the router and despite the Jail everything is working properly. Here are the "system" > "General" page as well as "Network" > "LAN Management" pages:
I would highly appreciate any kind of help that could stop me from pulling my hair already!
Thank you in advance!
Change IPv4 conf. from DHCP to static. And also send the log file from Extension - > TheBrig - > Log and select plex from the drop down menu and download it and send it only if changing from DHCP to static doesnt work. And happy happy honestly, no need to make any changes to the router settings.
Re: No internet connectivity inside of jail
Posted: 25 Jun 2014 21:19
by Chakalov
Hi,
I did all as instructed. Still no internet in nor out...
Here's the log file:
Code: Select all
Jun 1 17:47:08 OwnCloud newsyslog[2661]: logfile first created
Jun 1 17:47:08 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 22:53:33 OwnCloud syslogd: exiting on signal 15
Jun 1 22:55:07 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:05:50 OwnCloud syslogd: exiting on signal 15
Jun 1 23:09:55 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:09:55 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 1 23:15:39 OwnCloud syslogd: exiting on signal 15
Jun 1 23:16:47 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:16:47 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 4 12:22:46 OwnCloud syslogd: exiting on signal 15
Jun 4 12:28:25 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 4 12:28:25 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 11 13:11:03 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 11 13:11:04 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 20 23:14:42 OwnCloud syslogd: exiting on signal 15
Jun 20 23:20:42 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 20 23:20:42 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 22 17:33:08 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 22 17:33:09 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 25 02:12:54 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 25 02:12:54 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 25 22:09:26 OwnCloud syslogd: exiting on signal 15
Jun 25 22:14:39 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 25 22:14:39 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Thank you once again!
Re: No internet connectivity inside of jail
Posted: 27 Jun 2014 07:03
by chachi420
Chakalov wrote:Hi,
I did all as instructed. Still no internet in nor out...
Here's the log file:
Code: Select all
Jun 1 17:47:08 OwnCloud newsyslog[2661]: logfile first created
Jun 1 17:47:08 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 22:53:33 OwnCloud syslogd: exiting on signal 15
Jun 1 22:55:07 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:05:50 OwnCloud syslogd: exiting on signal 15
Jun 1 23:09:55 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:09:55 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 1 23:15:39 OwnCloud syslogd: exiting on signal 15
Jun 1 23:16:47 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 1 23:16:47 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 4 12:22:46 OwnCloud syslogd: exiting on signal 15
Jun 4 12:28:25 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 4 12:28:25 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 11 13:11:03 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 11 13:11:04 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 20 23:14:42 OwnCloud syslogd: exiting on signal 15
Jun 20 23:20:42 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 20 23:20:42 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 22 17:33:08 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 22 17:33:09 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 25 02:12:54 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 25 02:12:54 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Jun 25 22:09:26 OwnCloud syslogd: exiting on signal 15
Jun 25 22:14:39 OwnCloud syslogd: kernel boot file is /boot/kernel/kernel
Jun 25 22:14:39 OwnCloud root: /etc/rc.d/sysctl: WARNING: unable to set security.jail.allow_raw_sockets=1
Thank you once again!
Okey, got a question for you. Are you trying to fix plex or owncloud? I thought you were having problems with plex. Either way, if it's owncloud that you're having trouble with, it's actually really really simple to install owncloud and get it up and running. Follow these steps for owncloud integration.
1. turn on the webserver service and create a folder named 'www' in any of your mounts.
2. click on this link and download the zip file:
https://download.owncloud.org/community ... -6.0.3.zip
3. make a folder named 'owncloud' inside the www folder and extract the zip file in 'owncloud' folder
4. go to the browser and type this in: yourIP:port/owncloud/index.php (example 192.168.1.112:420/owncloud/index.php)
And it should be working then. I ask to install it this way because I am not sure why one would go about installing it in jail and all that hassle.
Now, if the problem is regarding plex, please send me the plex log, not owncloud.
Re: No internet connectivity inside of jail
Posted: 28 Jun 2014 18:01
by Chakalov
Please excuse my french. Didn't mean to cause confusion - it's all about OwnCloud and a NAS that I've build for a friend of mine. Plex is at home doing fine on my NAS.
Shortly after my last post here I decided to delete all jails and start everything from scratch. This time it worked like a charm with no issues at all. I suppose the problem was that I had set /32 mask on the Jail IP instead of /24 - that was perhaps the only difference. Didn't took care if it the first time because my Plex server is set on /32 and is working just fine. Either way OwnCloud installed and running just fine.
Putting OwnCould in a Jail is only because of security concerns despite the fact that I actually don't keep PDF's of China nuclear submarines blueprints (they are just elsewhere....). Guess you're more than right to install it right out of the jail.
Thank you once again!
Re: No internet connectivity inside of jail
Posted: 28 Jun 2014 18:37
by chachi420
Chakalov wrote:Please excuse my french. Didn't mean to cause confusion - it's all about OwnCloud and a NAS that I've build for a friend of mine. Plex is at home doing fine on my NAS.
Shortly after my last post here I decided to delete all jails and start everything from scratch. This time it worked like a charm with no issues at all. I suppose the problem was that I had set /32 mask on the Jail IP instead of /24 - that was perhaps the only difference. Didn't took care if it the first time because my Plex server is set on /32 and is working just fine. Either way OwnCloud installed and running just fine.
Putting OwnCould in a Jail is only because of security concerns despite the fact that I actually don't keep PDF's of China nuclear submarines blueprints (they are just elsewhere....). Guess you're more than right to install it right out of the jail.
Thank you once again!
Oh im glad its working now. A question though. Why is it more secured in jail though? I installed owncloud yesterday so that i can answer your questions and let you know the steps. I installed it the way i told you, just by aimply extracting the fles in a folder and first time i opened the index.php page, i could register but it did say something about .htaccess file and it said that .htaccess was not working and i needed to fix something or else my files would be accessible without protection. I couldn't solve the problem easily so let me know if you play around with it and figure it out. And your English is just fine btw buddy.
Re: No internet connectivity inside of jail
Posted: 29 Jun 2014 00:45
by Chakalov
A Jail doesn't have any access to the rest of your data that lives on the NAS except to one (=directories) you specifically and exclusively grant access to (via fstab). Then you could also specify permissions - say read only for example. Network restrictions could also be applied.
Consider Jail as even more isolated environment and since OwnCloud will be accessed through various devices and locations it's perhaps a better idea to set it in a jail. But then again it's not "that" easy and at least requires some additional attention. Above all essentially you should sit for a while and evaluate the sensitivity of the things you keep on the NAS. If there are some of those above mentioned Chinese submarine blueprints then better put it in a Jail, but if the blueprints are all about your dog's house than your more direct approach with the build in web server should do just fine.
In case you want to give Jail a try here are the guides that I've used:
https://www.youtube.com/watch?v=5AnUkYh2kzA
https://www.youtube.com/watch?v=bdXZsL_sj-I
Re: No internet connectivity inside of jail
Posted: 02 Jul 2014 01:27
by chachi420
Chakalov wrote:A Jail doesn't have any access to the rest of your data that lives on the NAS except to one (=directories) you specifically and exclusively grant access to (via fstab). Then you could also specify permissions - say read only for example. Network restrictions could also be applied.
Consider Jail as even more isolated environment and since OwnCloud will be accessed through various devices and locations it's perhaps a better idea to set it in a jail. But then again it's not "that" easy and at least requires some additional attention. Above all essentially you should sit for a while and evaluate the sensitivity of the things you keep on the NAS. If there are some of those above mentioned Chinese submarine blueprints then better put it in a Jail, but if the blueprints are all about your dog's house than your more direct approach with the build in web server should do just fine.
In case you want to give Jail a try here are the guides that I've used:
https://www.youtube.com/watch?v=5AnUkYh2kzA
https://www.youtube.com/watch?v=bdXZsL_sj-I
Awesome. Thanks Chakalov