vpn: accept forwarded guest traffic (FORWARD chain) + disable rp_filter on the veth; diagnose FORWARD chain

This commit is contained in:
Konstantin Passig PC
2026-08-25 18:15:26 +02:00
parent 5742f7fb63
commit 6aeffb81ab
+12 -1
View File
@@ -191,8 +191,16 @@ def up(cfg) -> None:
# tunnel is still down; wg-quick replaces it with the tunnel default below # tunnel is still down; wg-quick replaces it with the tunnel default below
_sudo(["ip", "netns", "exec", ns, "ip", "route", "add", "default", "via", _GUEST_GW], check=False) _sudo(["ip", "netns", "exec", ns, "ip", "route", "add", "default", "via", _GUEST_GW], check=False)
# 3. host forwards + NATs the namespace so it can reach the wg endpoint # 3. host forwards + NATs the namespace so it can reach the wg endpoint.
# The FORWARD ACCEPT rules matter: many hosts (firewalld, ufw, the
# Mullvad daemon's firewall) default-drop forwarded traffic, which would
# silently kill the namespace's handshake even though NAT is in place.
_sudo(["sysctl", "-w", "net.ipv4.ip_forward=1"]) _sudo(["sysctl", "-w", "net.ipv4.ip_forward=1"])
_sudo(["sysctl", "-w", "net.ipv4.conf.all.rp_filter=0"])
_sudo(["sysctl", "-w", f"net.ipv4.conf.{host_link}.rp_filter=0"])
for direction in ("-s", "-d"):
_sudo(["iptables", "-C", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False)
_sudo(["iptables", "-A", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"])
_sudo(["iptables", "-t", "nat", "-C", "POSTROUTING", _sudo(["iptables", "-t", "nat", "-C", "POSTROUTING",
"-s", _GUEST_NET, "-j", "MASQUERADE"], check=False) "-s", _GUEST_NET, "-j", "MASQUERADE"], check=False)
_sudo(["iptables", "-t", "nat", "-A", "POSTROUTING", _sudo(["iptables", "-t", "nat", "-A", "POSTROUTING",
@@ -216,6 +224,8 @@ def down(cfg) -> None:
_sudo(["ip", "netns", "del", ns], check=False) _sudo(["ip", "netns", "del", ns], check=False)
_sudo(["iptables", "-t", "nat", "-D", "POSTROUTING", _sudo(["iptables", "-t", "nat", "-D", "POSTROUTING",
"-s", _GUEST_NET, "-j", "MASQUERADE"], check=False) "-s", _GUEST_NET, "-j", "MASQUERADE"], check=False)
for direction in ("-s", "-d"):
_sudo(["iptables", "-D", "FORWARD", direction, _GUEST_NET, "-j", "ACCEPT"], check=False)
_sudo(["rm", "-f", f"/etc/wireguard/{iface}.conf"]) _sudo(["rm", "-f", f"/etc/wireguard/{iface}.conf"])
_sudo(["rm", "-rf", f"/etc/netns/{ns}"]) _sudo(["rm", "-rf", f"/etc/netns/{ns}"])
@@ -259,6 +269,7 @@ def _diagnose(cfg) -> str:
"for i in $(wg show interfaces 2>/dev/null); do " "for i in $(wg show interfaces 2>/dev/null); do "
"echo \"== $i ==\"; wg show $i public-key 2>/dev/null; done"]), "echo \"== $i ==\"; wg show $i public-key 2>/dev/null; done"]),
("host NAT", ["iptables", "-t", "nat", "-L", "POSTROUTING", "-n", "-v"]), ("host NAT", ["iptables", "-t", "nat", "-L", "POSTROUTING", "-n", "-v"]),
("host FORWARD", ["iptables", "-L", "FORWARD", "-n", "-v"]),
): ):
rc, out = _sudo_out(args) rc, out = _sudo_out(args)
parts.append(f"--- {title} ---\n{out or '(none)'}") parts.append(f"--- {title} ---\n{out or '(none)'}")