From 6aeffb81ab0f4839728b3134446f19536aee9a50 Mon Sep 17 00:00:00 2001 From: Konstantin Passig PC <2002erdi@gmail.com> Date: Tue, 25 Aug 2026 18:15:26 +0200 Subject: [PATCH] vpn: accept forwarded guest traffic (FORWARD chain) + disable rp_filter on the veth; diagnose FORWARD chain --- yt_downloader/vpn.py | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/yt_downloader/vpn.py b/yt_downloader/vpn.py index ab808cc..1b38521 100644 --- a/yt_downloader/vpn.py +++ b/yt_downloader/vpn.py @@ -191,8 +191,16 @@ def up(cfg) -> None: # tunnel is still down; wg-quick replaces it with the tunnel default below _sudo(["ip", "netns", "exec", ns, "ip", "route", "add", "default", "via", _GUEST_GW], check=False) - # 3. host forwards + NATs the namespace so it can reach the wg endpoint + # 3. host forwards + NATs the namespace so it can reach the wg endpoint. + # The FORWARD ACCEPT rules matter: many hosts (firewalld, ufw, the + # Mullvad daemon's firewall) default-drop forwarded traffic, which would + # silently kill the namespace's handshake even though NAT is in place. _sudo(["sysctl", "-w", "net.ipv4.ip_forward=1"]) + _sudo(["sysctl", "-w", "net.ipv4.conf.all.rp_filter=0"]) + _sudo(["sysctl", "-w", f"net.ipv4.conf.{host_link}.rp_filter=0"]) + for direction in ("-s", "-d"): + _sudo(["iptables", "-C", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False) + _sudo(["iptables", "-A", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"]) _sudo(["iptables", "-t", "nat", "-C", "POSTROUTING", "-s", _GUEST_NET, "-j", "MASQUERADE"], check=False) _sudo(["iptables", "-t", "nat", "-A", "POSTROUTING", @@ -216,6 +224,8 @@ def down(cfg) -> None: _sudo(["ip", "netns", "del", ns], check=False) _sudo(["iptables", "-t", "nat", "-D", "POSTROUTING", "-s", _GUEST_NET, "-j", "MASQUERADE"], check=False) + for direction in ("-s", "-d"): + _sudo(["iptables", "-D", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False) _sudo(["rm", "-f", f"/etc/wireguard/{iface}.conf"]) _sudo(["rm", "-rf", f"/etc/netns/{ns}"]) @@ -259,6 +269,7 @@ def _diagnose(cfg) -> str: "for i in $(wg show interfaces 2>/dev/null); do " "echo \"== $i ==\"; wg show $i public-key 2>/dev/null; done"]), ("host NAT", ["iptables", "-t", "nat", "-L", "POSTROUTING", "-n", "-v"]), + ("host FORWARD", ["iptables", "-L", "FORWARD", "-n", "-v"]), ): rc, out = _sudo_out(args) parts.append(f"--- {title} ---\n{out or '(none)'}")