LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-04-2022, 02:45 AM   #1
anetworkguy
LQ Newbie
 
Registered: Jul 2022
Posts: 1

Rep: Reputation: 0
Namespaces and firewalling


Hi network enthusiasts,

I'm working a project that requires two things:

- Being able to create pcap dump per PID
- Being able to force software to use a specific network card (while other are still used by other software)

Namespace seems to allow both. I'm able, using some tricks and scripts to create on the fly namespace on which I execute a given software and dump flow for the virtual NIC associated.

As for the second point, I'm currently doing more tests. My problem is that i need a software (openvpn in this case), to use a specific NIC. Openvpn seems not to have a native option for that. Forcing using route is not an option since the VPN endpoint will be given as a hostname rather an ip (mandatory).

Using namespace allows to restrict openvpn to only the good interface. However, after that, I tried to restrict the system (and other namespace) to enforce security.

While trying to update my knowledge on modern networking and using UFW instead of iptables, I went into a strange behavior.

I had to enable UFW for each namespace, but rules are "likely" shared: They are shown when asking for status. If I had a rule on system, it's shown on namespaces. And adding it on namespace make it visible from system.

But the rules are not correctly applied. In other word: Once the NIC is attached to my namespace (and not visible from system anymore), I can add rules but they wont work unless removed from where they were created (system or other namespace) and added from needed namespace.

On iptables, rules are not shared and you have to add create everything on each namespace.

As anyone notice such a thing?

(Tests made on up-to-date Archlinux).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables rule placement and other firewalling questions wierdbeard65 Linux - Security 6 10-13-2012 10:08 AM
[putty&ssh] Who is really good & expert in ssh https tunnelling and firewalling ? Xeratul Linux - General 12 12-03-2006 03:22 AM
Tip: Randomizing and firewalling your tcp port range scottman Linux - Security 6 10-02-2004 12:42 AM
Kernel 2.4.* and firewalling projfw Linux - Newbie 3 08-01-2001 07:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration