Update VPN with Traffic Splitting page

chros73
2018-05-27 13:31:27 +01:00
parent 5a99722926
commit 0b38b0d1df
+28 -12
@@ -27,17 +27,26 @@ First, you need to install a few **required** packages. These steps must be perf
.. code-block:: shell
apt-get update
apt-get install openvpn ip python sudo dnsutils dnsmasq curl
apt-get install openvpn iproute2 python sudo dnsutils dnsmasq curl
Download `namespaced-openvpn <https://raw.githubusercontent.com/slingamn/namespaced-openvpn/master/namespaced-openvpn>`_ script into ``/usr/local/sbin`` directory:
.. code-block:: shell
cd /usr/local/sbin && curl -sLSO https://raw.githubusercontent.com/slingamn/namespaced-openvpn/master/namespaced-openvpn
cd /usr/local/sbin
curl -sLSO https://raw.githubusercontent.com/slingamn/namespaced-openvpn/master/namespaced-openvpn
chmod +x namespaced-openvpn
Then copy the provided OpenVPN ``*.ovpn`` config file(s) into ``/etc/openvpn`` directory.
Then copy the provided OpenVPN ``*.ovpn`` config file(s) into ``~/.config/openvpn`` directory as a regular user after creating that directory:
.. code-block:: shell
mkdir -p ~/.config/openvpn
cp *.ovpn ~/.config/openvpn/
chmod 400 ~/.config/openvpn/*.ovpn
Basic usage
@@ -47,14 +56,15 @@ To create an OpenVPN tunnel in the ``protected`` (default) namespace (change ``f
.. code-block:: shell
sudo /usr/local/sbin/namespaced-openvpn --config /etc/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon
sudo /usr/local/sbin/namespaced-openvpn --config /home/"$USER"/.config/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon
To start an application in the ``protected`` namespace:
.. code-block:: shell
sudo ip netns exec protected sudo -u "$USER" rtorrent
sudo ip netns exec protected sudo -u "$USER" ip addr show
sudo ip netns exec protected sudo -u "$USER" dig
To start an interactive shell in the ``protected`` namespace (every other commands will be started in the same namespace):
@@ -64,7 +74,14 @@ To start an interactive shell in the ``protected`` namespace (every other comma
sudo ip netns exec protected sudo -u "$USER" -i
To stop the OpenVPN tunnel just ``kill`` the process:
To get a list of available namespaces:
.. code-block:: shell
ip netns list
To stop the OpenVPN tunnel just ``kill`` the process, note that ``protected`` namespace is still available!:
.. code-block:: shell
@@ -110,10 +127,9 @@ Only the following changes are needed in ``.rtorrent.rc``:
# UDP port to use for DHT
dht.port.set = 64229
# SCGI socket and make it group writeable when rtorrent starts (otherwise apps can't connect to it since it was
started by a normal user) (scgi_local)
network.scgi.open_local = /tmp/.rtorrent.sock
schedule2 = chmod_scgi_socket, 0, 0, "execute2=chmod,g+w,/tmp/.rtorrent.sock"
# SCGI socket and make it group writeable when rtorrent starts (otherwise apps can't connect to it since it was started by a normal user) (scgi_local)
network.scgi.open_local = /path/to/session/dir/.rtorrent.sock
schedule2 = chmod_scgi_socket, 0, 0, "execute2=chmod,g+w,(cat,(session.path),.rtorrent.sock)"
# Get public IP address without the need of having dynamic DNS service, also works from behind NAT, through tunnel
method.insert = get_public_ip_address, simple|private, "execute.capture=bash,-c,\"eval echo -n \$(dig TXT +short o-o.myaddr.l.google.com @ns1.google.com)\""
@@ -128,7 +144,7 @@ We can even have caching DNS in the ``protected`` namespace by using ``dnsmasq``
.. code-block:: shell
netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/netns/dnsmasq-protected-"$USER".pid
netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/dnsmasq-protected-foo-"$USER".pid
Summary
@@ -144,7 +160,7 @@ After setting up our system, the following commands will:
.. code-block:: shell
sudo /usr/local/sbin/namespaced-openvpn --config /etc/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon
netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/netns/dnsmasq-protected-"$USER".pid
netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/dnsmasq-protected-foo-"$USER".pid
netns-exec rtorrent