diff --git a/VPN-with-Traffic-Splitting.rest b/VPN-with-Traffic-Splitting.rest index 4c18835..e24271f 100644 --- a/VPN-with-Traffic-Splitting.rest +++ b/VPN-with-Traffic-Splitting.rest @@ -27,17 +27,26 @@ First, you need to install a few **required** packages. These steps must be perf .. code-block:: shell apt-get update - apt-get install openvpn ip python sudo dnsutils dnsmasq curl + apt-get install openvpn iproute2 python sudo dnsutils dnsmasq curl Download `namespaced-openvpn `_ script into ``/usr/local/sbin`` directory: .. code-block:: shell - cd /usr/local/sbin && curl -sLSO https://raw.githubusercontent.com/slingamn/namespaced-openvpn/master/namespaced-openvpn + cd /usr/local/sbin + curl -sLSO https://raw.githubusercontent.com/slingamn/namespaced-openvpn/master/namespaced-openvpn + chmod +x namespaced-openvpn -Then copy the provided OpenVPN ``*.ovpn`` config file(s) into ``/etc/openvpn`` directory. +Then copy the provided OpenVPN ``*.ovpn`` config file(s) into ``~/.config/openvpn`` directory as a regular user after creating that directory: + +.. code-block:: shell + + mkdir -p ~/.config/openvpn + cp *.ovpn ~/.config/openvpn/ + chmod 400 ~/.config/openvpn/*.ovpn + Basic usage @@ -47,14 +56,15 @@ To create an OpenVPN tunnel in the ``protected`` (default) namespace (change ``f .. code-block:: shell - sudo /usr/local/sbin/namespaced-openvpn --config /etc/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon + sudo /usr/local/sbin/namespaced-openvpn --config /home/"$USER"/.config/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon To start an application in the ``protected`` namespace: .. code-block:: shell - sudo ip netns exec protected sudo -u "$USER" rtorrent + sudo ip netns exec protected sudo -u "$USER" ip addr show + sudo ip netns exec protected sudo -u "$USER" dig To start an interactive shell in the ``protected`` namespace (every other commands will be started in the same namespace): @@ -64,7 +74,14 @@ To start an interactive shell in the ``protected`` namespace (every other comma sudo ip netns exec protected sudo -u "$USER" -i -To stop the OpenVPN tunnel just ``kill`` the process: +To get a list of available namespaces: + +.. code-block:: shell + + ip netns list + + +To stop the OpenVPN tunnel just ``kill`` the process, note that ``protected`` namespace is still available!: .. code-block:: shell @@ -110,10 +127,9 @@ Only the following changes are needed in ``.rtorrent.rc``: # UDP port to use for DHT dht.port.set = 64229 - # SCGI socket and make it group writeable when rtorrent starts (otherwise apps can't connect to it since it was - started by a normal user) (scgi_local) - network.scgi.open_local = /tmp/.rtorrent.sock - schedule2 = chmod_scgi_socket, 0, 0, "execute2=chmod,g+w,/tmp/.rtorrent.sock" + # SCGI socket and make it group writeable when rtorrent starts (otherwise apps can't connect to it since it was started by a normal user) (scgi_local) + network.scgi.open_local = /path/to/session/dir/.rtorrent.sock + schedule2 = chmod_scgi_socket, 0, 0, "execute2=chmod,g+w,(cat,(session.path),.rtorrent.sock)" # Get public IP address without the need of having dynamic DNS service, also works from behind NAT, through tunnel method.insert = get_public_ip_address, simple|private, "execute.capture=bash,-c,\"eval echo -n \$(dig TXT +short o-o.myaddr.l.google.com @ns1.google.com)\"" @@ -128,7 +144,7 @@ We can even have caching DNS in the ``protected`` namespace by using ``dnsmasq`` .. code-block:: shell - netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/netns/dnsmasq-protected-"$USER".pid + netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/dnsmasq-protected-foo-"$USER".pid Summary @@ -144,7 +160,7 @@ After setting up our system, the following commands will: .. code-block:: shell sudo /usr/local/sbin/namespaced-openvpn --config /etc/openvpn/foo.ovpn --writepid /var/run/openvpn-protected-foo-"$USER".pid --log /var/log/openvpn-protected-foo-"$USER".log --daemon - netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/netns/dnsmasq-protected-"$USER".pid + netns-exec /usr/sbin/dnsmasq --bind-interfaces --listen-address=127.0.1.1 --server=8.8.8.8 --server 8.8.8.4 --cache-size=500 --proxy-dnssec --pid-file=/var/run/dnsmasq-protected-foo-"$USER".pid netns-exec rtorrent