vpn: accept forwarded guest traffic (FORWARD chain) + disable rp_filter on the veth; diagnose FORWARD chain
This commit is contained in:
+12
-1
@@ -191,8 +191,16 @@ def up(cfg) -> None:
|
||||
# tunnel is still down; wg-quick replaces it with the tunnel default below
|
||||
_sudo(["ip", "netns", "exec", ns, "ip", "route", "add", "default", "via", _GUEST_GW], check=False)
|
||||
|
||||
# 3. host forwards + NATs the namespace so it can reach the wg endpoint
|
||||
# 3. host forwards + NATs the namespace so it can reach the wg endpoint.
|
||||
# The FORWARD ACCEPT rules matter: many hosts (firewalld, ufw, the
|
||||
# Mullvad daemon's firewall) default-drop forwarded traffic, which would
|
||||
# silently kill the namespace's handshake even though NAT is in place.
|
||||
_sudo(["sysctl", "-w", "net.ipv4.ip_forward=1"])
|
||||
_sudo(["sysctl", "-w", "net.ipv4.conf.all.rp_filter=0"])
|
||||
_sudo(["sysctl", "-w", f"net.ipv4.conf.{host_link}.rp_filter=0"])
|
||||
for direction in ("-s", "-d"):
|
||||
_sudo(["iptables", "-C", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False)
|
||||
_sudo(["iptables", "-A", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"])
|
||||
_sudo(["iptables", "-t", "nat", "-C", "POSTROUTING",
|
||||
"-s", _GUEST_NET, "-j", "MASQUERADE"], check=False)
|
||||
_sudo(["iptables", "-t", "nat", "-A", "POSTROUTING",
|
||||
@@ -216,6 +224,8 @@ def down(cfg) -> None:
|
||||
_sudo(["ip", "netns", "del", ns], check=False)
|
||||
_sudo(["iptables", "-t", "nat", "-D", "POSTROUTING",
|
||||
"-s", _GUEST_NET, "-j", "MASQUERADE"], check=False)
|
||||
for direction in ("-s", "-d"):
|
||||
_sudo(["iptables", "-D", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False)
|
||||
_sudo(["rm", "-f", f"/etc/wireguard/{iface}.conf"])
|
||||
_sudo(["rm", "-rf", f"/etc/netns/{ns}"])
|
||||
|
||||
@@ -259,6 +269,7 @@ def _diagnose(cfg) -> str:
|
||||
"for i in $(wg show interfaces 2>/dev/null); do "
|
||||
"echo \"== $i ==\"; wg show $i public-key 2>/dev/null; done"]),
|
||||
("host NAT", ["iptables", "-t", "nat", "-L", "POSTROUTING", "-n", "-v"]),
|
||||
("host FORWARD", ["iptables", "-L", "FORWARD", "-n", "-v"]),
|
||||
):
|
||||
rc, out = _sudo_out(args)
|
||||
parts.append(f"--- {title} ---\n{out or '(none)'}")
|
||||
|
||||
Reference in New Issue
Block a user