On 2026-10-06 16:59, Mike Larkin wrote:
On Tue, Oct 06, 2026 at 08:02:18AM +0000, Sylvain Saboua wrote:
Here you go, I followed the FAQ strictly applying option 4
instructions again. Weirdly, I can't reach the network from
the vm if I use the following vm.conf:
switch "my_switch" { interface veb0 }
vm alpine {
        memory 4G
        boot device cdrom
        disk /var/www/jellyfin/alpine.qcow2
        #cdrom /var/www/jellyfin/alpine-virt-3.24.2-x86_64.iso
        local interface { switch "my_switch" }
}

Instead, I have to launch the vm using the following command:
vmctl start -c -L -i 1 -B disk -d alpine.qcow2 -m 4G alpine

This is not a big deal, but then I have the same problem as
before (in the configuration I had prior to the previous mail):
I can reach (ping) any local machine or remote website from the
vm, yet the opposite is not true.

How should I configure the Alpine vm / OpenBSD server host so
that the former can be reached through the LAN ?

Here is my current configuration:
srv$ ifconfig
lo0: flags=2008049<UP,LOOPBACK,RUNNING,MULTICAST,LRO> mtu 32768
        index 4 priority 0 llprio 3
        groups: lo
        inet6 ::1 prefixlen 128
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4
        inet 127.0.0.1 netmask 0xff000000
re0: flags=8b43<UP,BROADCAST,RUNNING,PROMISC,ALLMULTI,SIMPLEX,MULTICAST> mtu
1500
        lladdr 08:60:6e:eb:54:8b
        index 1 priority 0 llprio 3
        media: Ethernet autoselect (1000baseT
full-duplex,master,rxpause,txpause)
        status: active
athn0: flags=a48843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,AUTOCONF6TEMP,AUTOCONF6,AUTOCONF4>
mtu 1500
        lladdr 00:26:b6:f5:be:78
        index 2 priority 4 llprio 3
        groups: wlan egress
        media: IEEE802.11 autoselect (HT-MCS1 mode 11n)
        status: active
ieee80211: join sylvainsab chan 100 bssid c0:3c:04:fc:d5:94 -67dBm
wpakey wpaprotos wpa2 wpaakms psk wpaciphers ccmp wpagroupcipher ccmp
        inet6 fe80::226:b6ff:fef5:be78%athn0 prefixlen 64 scopeid 0x2
        inet 10.0.0.2 netmask 0xffffff00 broadcast 10.0.0.255
inet6 2001:861:2c20:70:2e50:4d99:c696:826e prefixlen 64 autoconf
temporary pltime 13995 vltime 85995
inet6 2001:861:2c20:70:fade:a8c6:347a:3d91 prefixlen 64 autoconf
pltime 13995 vltime 85995
enc0: flags=0<>
        index 3 priority 0 llprio 3
        groups: enc
        status: active
veb0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST>
        description: switch1-my_switch
        index 5 llprio 3
        encap: vnetid 1 txprio packet rxprio outer
        groups: veb
        re0 flags=3<LEARNING,DISCOVER>
                port 1 ifpriority 0 ifcost 0 untagged 1
                tagged: none
        vport0 flags=3<LEARNING,DISCOVER>
                port 6 ifpriority 0 ifcost 0 untagged 1
vport0: flags=a48943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,AUTOCONF6TEMP,AUTOCONF6,AUTOCONF4>
mtu 1500
        lladdr 0e:aa:bb:cc:dd:ee
        index 6 priority 0 llprio 3
        groups: vport egress
        inet6 fe80::caa:bbff:fecc:ddee%vport0 prefixlen 64 scopeid 0x6
inet6 2001:861:2c20:70:6183:a02e:8347:97ea prefixlen 64 autoconf
pltime 13995 vltime 85995
inet6 2001:861:2c20:70:9a19:8207:d5c9:5d50 prefixlen 64 autoconf
temporary pltime 13995 vltime 85995
        inet 10.0.0.111 netmask 0xffffff00 broadcast 10.0.0.255
pflog0: flags=141<UP,RUNNING,PROMISC> mtu 33136
        index 7 priority 0 llprio 3
        groups: pflog

srv$ cat /etc/hostname.athn0
join sylvainsab wpakey cee93RAJ34npqNzf4G
inet autoconf
inet6 autoconf
srv$ cat /etc/hostname.re0
up
srv$ cat /etc/hostname.veb0
add re0
add vport0
up
srv$ cat /etc/hostname.vport0
lladdr 0E:AA:BB:CC:DD:EE
inet autoconf
inet6 autoconf
up

media:~# ifconfig
docker0   Link encap:Ethernet  HWaddr DA:C6:BF:90:51:3D
          inet addr:172.17.0.1  Bcast:172.17.255.255  Mask:255.255.0.0
          inet6 addr: fe80::d8c6:bfff:fe90:513d/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:77 errors:0 dropped:0 overruns:0 frame:0
          TX packets:91 errors:0 dropped:2 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:7608 (7.4 KiB)  TX bytes:217425 (212.3 KiB)

eth0      Link encap:Ethernet  HWaddr FE:E1:BB:D1:29:99
          inet addr:100.64.1.3  Bcast:0.0.0.0  Mask:255.255.255.254
          inet6 addr: fe80::fce1:bbff:fed1:2999/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:196 errors:0 dropped:0 overruns:0 frame:0
          TX packets:130 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:226495 (221.1 KiB)  TX bytes:14614 (14.2 KiB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:65536  Metric:1
          RX packets:2 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:140 (140.0 B)  TX bytes:140 (140.0 B)

vetha5b71ac Link encap:Ethernet  HWaddr 2E:86:1D:4A:16:D8
          inet6 addr: fe80::2c86:1dff:fe4a:16d8/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:77 errors:0 dropped:0 overruns:0 frame:0
          TX packets:102 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:8686 (8.4 KiB)  TX bytes:218291 (213.1 KiB)

On 2026-10-06 06:40, Sylvain Saboua wrote:
> Following on that vmm/Alpine/Docker/Jellyfin install:
> I should now be able, according to the Docker documentation,
> to log into the Jellyfin server administration interface
> through http://myalpinevm:8096/ (in place of localhost)
>
> However, for this I need my vm to be accessible through
> the local network as if it were any other regular device
> connected to my ISP's box that acts as a router. If I
> understand correctly, this is described in the last section
> (Option 4 - VMs on the real network) of the FAQ.
>
> Following that tutorial, I have tried various configurations
> without success.
>
> As of now, I have omitted vport0 in the configuration as per
> the last sentence in the FAQ. Not sure if I should have been
> doing something else as well.
>
> Currently my ethernet device eth0 has been disconnected.
> I can still access my server through the wireless athn0 device.
>
> Here is what I have:
>
> srv$ more /etc/hostname.re0
> inet autoconf
> inet6 autoconf
> srv$ more /etc/hostname.veb0
> add re0
> up
>
> srv$ ifconfig
> lo0: flags=2008049<UP,LOOPBACK,RUNNING,MULTICAST,LRO> mtu 32768
>         index 4 priority 0 llprio 3
>         groups: lo
>         inet6 ::1 prefixlen 128
>         inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4
>         inet 127.0.0.1 netmask 0xff000000
> re0: 
flags=a48b43<UP,BROADCAST,RUNNING,PROMISC,ALLMULTI,SIMPLEX,MULTICAST,AUTOCONF6TEMP,AUTOCONF6,AUTOCONF4>
> mtu 1500
>         lladdr 08:60:6e:eb:54:8b
>         index 1 priority 0 llprio 3
>         media: Ethernet autoselect (1000baseT
> full-duplex,rxpause,txpause)
>         status: active
>         inet6 fe80::a60:6eff:feeb:548b%re0 prefixlen 64 scopeid 0x1
> athn0: 
flags=a48843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,AUTOCONF6TEMP,AUTOCONF6,AUTOCONF4>
> mtu 1500
>         lladdr 00:26:b6:f5:be:78
>         index 2 priority 4 llprio 3
>         groups: wlan egress
>         media: IEEE802.11 autoselect (HT-MCS3 mode 11n)
>         status: active
>         ieee80211: join sylvainsab chan 100 bssid c0:3c:04:fc:d5:94
> -71dBm wpakey wpaprotos wpa2 wpaakms psk wpaciphers ccmp wpagroupcipher
> ccmp
>         inet6 fe80::226:b6ff:fef5:be78%athn0 prefixlen 64 scopeid 0x2
>         inet 10.0.0.2 netmask 0xffffff00 broadcast 10.0.0.255
>         inet6 2001:861:2c20:70:36ec:9a07:7fcd:50c5 prefixlen 64 autoconf
> temporary pltime 14397 vltime 86397
>         inet6 2001:861:2c20:70:fade:a8c6:347a:3d91 prefixlen 64 autoconf
> pltime 14397 vltime 86397
> enc0: flags=0<>
>         index 3 priority 0 llprio 3
>         groups: enc
>         status: active
> veb0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST>
>         description: switch1-my_switch
>         index 5 llprio 3
>         encap: vnetid 1 txprio packet rxprio outer
>         groups: veb
>         re0 flags=3<LEARNING,DISCOVER>
>                 port 1 ifpriority 0 ifcost 0 untagged 1
>                 tagged: none
>         tap0 flags=3<LEARNING,DISCOVER>
>                 port 7 ifpriority 0 ifcost 0 untagged 1
>                 tagged: none
> pflog0: flags=141<UP,RUNNING,PROMISC> mtu 33136
>         index 6 priority 0 llprio 3
>         groups: pflog
> tap0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu
> 1500
>         lladdr fe:e1:ba:d0:a7:aa
>         description: vm1-if0-alpine
>         index 7 priority 0 llprio 3
>         groups: tap
>         status: active
>
> I might try exactly following the FAQ as I did before,
> i.e. not omitting vport0, but I am not very hopeful.
> In any case, can you confirm that there is a way to
> configure the network so that I can access my vm to
> and from my other LAN machines ? Previously I was able
> to ping any machine from the vm but not vice-versa.
> Does it have to do with the limitations of using one's
> ISP's box as router ?
>
> Cheers

--
Sylvain Saboua
looking for a PDP-11


if "to and from my other LAN machines" means "not from the host running vmd",
then you need something in pf.conf on the host:

pass in on ext proto tcp from any to any port 8096 rdr-to vm-addr port 8096

Where:

ext = external interface on the vmd server machine
vm-addr = ip address of the vm

and also make sure there aren't any other conflicting pf rules that would
undo this change later in the file.

for example, I do the same thing you want to do and this is what I have:

pass in on trunk0 proto tcp from any to any port 8096 rdr-to 172.16.19.83 port 8096

but obviously don't copy mine blindly; fix it up for your own scenario.

and if it doesnt work, then just use tcpdump on the enroute interfaces to find out where the packet is being dropped, and pfctl to look at what's going on there.

Thanks ! Here's the lines I've added to my pf.conf:
# Enable vm to be reachable from the LAN
ext = "vport0"
vm_addr = "100.64.1.3"
pass in on $ext proto tcp from any to any port 8096 rdr-to $vm_addr port 8096

Now I'm watching my first locally stored music clip from my server on my
smart TV ! Left with hardlinking the other media files with Jellyfin naming
conventions ... and, who knows, blocking the smart TV from accessing the
internet as per https://marc.info/?t=178945888300004&r=1&w=2
https://fabricati-diem.inform.social/post/deshittification-as-a-service/
(although I supposed it would also be enough to block all outcomig traffic
from the TV to the outside network on my ISP's box)

Oh, and I'm still starting the vm using vmctl, not vm.conf, since when I
tried last I was unable to connect to the network (either local or wide)
with the latter. This is no big deal for now.

Cheers !
--
Sylvain Saboua
looking for a PDP-11

Reply via email to