Skip to content

Namesspace, ip netns tun0, pvpnksintrf0 . #6384

Answered by realjench
realjench asked this question in Q&A
Discussion options

You must be logged in to vote

@glitsj16

I've been down the rabbit hole of ancient debates about that pesky layer 3 tun0 problem, which seems destined to never get native firejail support. I've tried every namespace bridge trick and tun0 shuffle... The secret sauce? It's iptables!

But the real star of the show is opensnitch (Be sure to use this version, it's highly customizable!

) with its delightful GUI, making it super adjustable!

To add an extra layer of security, I've even put the VM on lockdown from the host, letting it chat only with the VPN server. So, I'm feeling pretty good about firejailing with apparmor (each doing its own thing). Fingers crossed, right? SELINUX might be the belle of the ball, but...

And voi…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@realjench
Comment options

Answer selected by realjench
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants