You are not logged in.
Hi,
My goal is to set up a network namespace including openvpn and to bridge some connections outside of this namespace (port 9091, transmission web GUI).
What I did :
Create an openvpn systemd unit which starts the namespace. I don't remember where I found this but I think it is pretty neat to handle the namespace in the openvpn service: /usr/lib/systemd/system/openvpn-client@.service
[Unit]
Description=OpenVPN tunnel for %I
After=syslog.target network-online.target
Wants=network-online.target
Documentation=man:openvpn(8)
Documentation=https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
Documentation=https://community.openvpn.net/openvpn/wiki/HOWTO
[Service]
Type=notify
PrivateTmp=true
WorkingDirectory=/etc/openvpn/client
ExecStart=/usr/bin/openvpn --script-security 2 --ifconfig-noexec --route-noexec --up /etc/openvpn/netns-script --route-up /etc/openvpn/netns-script --down /etc/openvpn/netns-script --suppress-timestamps --nobind --config %i.conf
CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE
LimitNPROC=10
DeviceAllow=/dev/null rw
DeviceAllow=/dev/net/tun rw
ProtectSystem=true
ProtectHome=true
KillMode=process
[Install]
WantedBy=multi-user.target
EOFThis is the script called by openvpn and managing the namespace (with debug info):
#!/bin/sh
set -o xtrace
case $script_type in
up)
echo " this script is running as $(id -u -n)"
ip netns add vpn
ip netns exec vpn ip link set dev lo up
ip link set dev "$1" up netns vpn mtu "$2"
ip netns exec vpn ip addr add dev "$1" \
"$4/${ifconfig_netmask:-30}" \
${ifconfig_broadcast:+broadcast "$ifconfig_broadcast"}
if [ -n "$ifconfig_ipv6_local" ]; then
ip netns exec vpn ip addr add dev "$1" \
"$ifconfig_ipv6_local"/112
fi
ip link add name vethhost0 type veth peer name vethvpn0
ip link set vethvpn0 netns vpn
ip addr add 10.0.0.1/24 dev vethhost0
ip netns exec vpn ip addr add 10.0.0.2/24 dev vethvpn0
ip link set vethhost0 up
ip netns exec vpn ip link set vethvpn0 up
iptables -t nat -A PREROUTING ! -s 10.0.0.0/24 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
ip netns exec vpn ip route add default via 10.0.0.1
iptables -t nat -A POSTROUTING -d 10.0.0.2/24 -j SNAT --to-source 10.0.0.1
iptables -t nat -A OUTPUT -d 192.168.10.1 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
;;
route-up)
ip netns exec vpn ip route add default via "$route_vpn_gateway"
if [ -n "$ifconfig_ipv6_remote" ]; then
ip netns exec vpn ip route add default via \
"$ifconfig_ipv6_remote"
fi
;;
down)
ip netns delete vpn
;;
esacMake sure root is running it:
chmod 740 /etc/openvpn/netns-script
chmod u+s /etc/openvpn/netns-script
ls -l /etc/openvpn/netns-script
-rwsr----- 1 root root 1813 Nov 22 22:18 /etc/openvpn/netns-scriptBut when I start openvpn with sudo:
systemctl start openvpn-client@chire.serviceThe output of 'journalctl -eu openvpn-client@chire.service' tells me that some operations are not permitted :
Nov 22 22:18:44 rexthor openvpn[5958]: /etc/openvpn/netns-script tun0 1500 1552 10.8.0.18 10.8.0.17 init
Nov 22 22:18:44 rexthor openvpn[5958]: + case $script_type in
Nov 22 22:18:44 rexthor openvpn[5958]: ++ id -u -n
Nov 22 22:18:44 rexthor openvpn[5958]: + echo ' this script is running as root'
Nov 22 22:18:44 rexthor openvpn[5958]: this script is running as root
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns add vpn
Nov 22 22:18:44 rexthor openvpn[5958]: mount --make-shared /var/run/netns failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip link set dev lo up
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set dev tun0 up netns vpn mtu 1500
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip addr add dev tun0 10.8.0.18/30
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + '[' -n '' ']'
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link add name vethhost0 type veth peer name vethvpn0
Nov 22 22:18:44 rexthor openvpn[5958]: RTNETLINK answers: File exists
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set vethvpn0 netns vpn
Nov 22 22:18:44 rexthor openvpn[5958]: Cannot find device "vethvpn0"
Nov 22 22:18:44 rexthor openvpn[5958]: + ip addr add 10.0.0.1/24 dev vethhost0
Nov 22 22:18:44 rexthor openvpn[5958]: RTNETLINK answers: File exists
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip addr add 10.0.0.2/24 dev vethvpn0
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set vethhost0 up
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip link set vethvpn0 up
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A PREROUTING '!' -s 10.0.0.0/24 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip route add default via 10.0.0.1
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A POSTROUTING -d 10.0.0.2/24 -j SNAT --to-source 10.0.0.1
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A OUTPUT -d 192.168.10.1 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
Nov 22 22:18:44 rexthor openvpn[5958]: + case $script_type in
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip route add default via 10.8.0.17
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + '[' -n '' ']'
Nov 22 22:18:44 rexthor openvpn[5958]: GID set to nobody
Nov 22 22:18:44 rexthor openvpn[5958]: UID set to nobody
Nov 22 22:18:44 rexthor openvpn[5958]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Nov 22 22:18:44 rexthor openvpn[5958]: Initialization Sequence CompletedMake sure the right openvpn service is running:
ystemctl status openvpn-client@chire.service 22:35:19 ✔ 0
● openvpn-client@chire.service - OpenVPN tunnel for chire
Loaded: loaded (/usr/lib/systemd/system/openvpn-client@.service; disabled; vendor preset: disabled)
Active: active (running) since Fri 2019-11-22 22:18:42 CET; 17min ago
Docs: man:openvpn(8)
https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
https://community.openvpn.net/openvpn/wiki/HOWTO
Main PID: 5958 (openvpn)
Status: "Initialization Sequence Completed"
Tasks: 1 (limit: 4475)
Memory: 2.6M
CGroup: /system.slice/system-openvpn\x2dclient.slice/openvpn-client@chire.service
└─5958 /usr/bin/openvpn --script-security 2 --ifconfig-noexec --route-noexec --up /etc/openvpn/netns-script --route-up /etc/openvpn/netns-script --down /etc/openvpn/netns-script --suppress-timestamps --nobind --config chire.confWhy is root not permitted to do 'ip netns' ? It works when running these commands with sudo.
The second disturbing point is that 'ip link ...' does not complain, only 'ip netns'.
Thanks,
Last edited by elkami (2019-11-23 15:42:33)
Offline
Does https://serverfault.com/questions/80795 … y-if-openv answer your question?
Offline
Yes it does, thanks!
adding 'CAP_SYS_ADMIN' to the openvpn service file 'CapabilityBoundingSet' property works.
I still don't understand how I didn't found this post ealrlier...
Offline