You are not logged in.

#1 2020-02-05 09:39:54

Gregosky
Member
From: UK
Registered: 2013-07-26
Posts: 184

[SOLVED] Why does `ip link set dev tun0 up` not bring tun0 up

This is newbie question and I have spent quite some time trying to do something that might be not possible.

I'm trying to create tun0 interface, assign it with the IP address and then bring it up. I need this because I am running openvpn in unprivileged container and I would like to attach it to that tun0 interface.

So I do something like this:

ip tuntap add mode tun dev tun0 user my_unprivileged_user group my_unprivileged_group
ip addr add 10.254.254.1/24 dev tun0
ip link set dev tun0 up

But `ip a` shows this interface in DOWN state:

11: tun0: <NO-CARRIER,POINTOPOINT,MULTICAST,NOARP,UP> mtu 1500 qdisc fq_codel state DOWN group default qlen 500
link/none

Even though journal shows that link was set to UP..

Feb 05 09:36:27 unknown systemd-udevd[2664]: ethtool: autonegotiation is unset or enabled, the speed and duplex are not writable.
Feb 05 09:36:27 unknown systemd-networkd[1167]: tun0: Link UP

If I pass this interface like that to my unprivileged container then openvpn tries to bring this interface up and fails (since it's unprivileged container). So I understand I have to make it to show up in UP state before starting openvpn...

So I also tried to create tun0 with systemd, I added tun0.netdev to /etc/systemd/network:

[NetDev]
Name=tun0
Kind=tun

[Tun]
User=my_unprivileged_user
Group=my_unprivileged_group

and also tun0.network:

[Match]
Name=tun0

[Network]
Address=10.254.254.1/24

[Link]
MTUBytes=1500

But when I restart the systemd-networkd I get tun0 without IP address and in DOWN state - I noticed it would be in UP state for very brief period of time and then log to journal:

Feb 05 09:50:35 unknown systemd-networkd[2704]: tun0: Gained carrier
Feb 05 09:50:36 unknown systemd-networkd[2704]: tun0: Lost carrier

Is it possible to make this interface to stay in UP state?

I found a post from 2010 where somebody was successfully doing this but I guess kernel must have changed since then and so behavior of tun also changed. Since this is software interface then I have to somehow emulate the wire being attached to it?

Last edited by Gregosky (2020-02-05 11:10:28)

Offline

#2 2020-02-05 09:54:52

Slithery
Administrator
From: Norfolk, UK
Registered: 2013-12-01
Posts: 5,776

Re: [SOLVED] Why does `ip link set dev tun0 up` not bring tun0 up

Gregosky wrote:

But `ip a` shows this interface in DOWN state:

11: tun0: <NO-CARRIER,POINTOPOINT,MULTICAST,NOARP,UP> mtu 1500 qdisc fq_codel state DOWN group default qlen 500
link/none

That output clearly states that the interface is up (look between the brackets).


No, it didn't "fix" anything. It just shifted the brokeness one space to the right. - jasonwryan
Closing -- for deletion; Banning -- for muppetry. - jasonwryan

aur - dotfiles

Offline

#3 2020-02-05 10:02:26

Gregosky
Member
From: UK
Registered: 2013-07-26
Posts: 184

Re: [SOLVED] Why does `ip link set dev tun0 up` not bring tun0 up

Thanks @Slithery, so does `state DOWN` mean that there is simply no traffic going on? Openvpn "thinks" the interface is down and tries to run `ip link set dev tun0 up mtu 1500` (within the unprivileged container) and fails

----

I'm wrong, openvpn tries to update MTU and fails while trying to do that.

I ended up replacing `/usr/bin/ip` from within the container with `exit 0` bash script...

Last edited by Gregosky (2020-02-05 11:10:11)

Offline

Board footer

Powered by FluxBB