Have you seen/read http://www.freebsd.org/doc/handbook/jails.html ? In many cases that is a suitable alternative to running VMs.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|