You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mininet+Faucet环境下Chewie无法捕获命名空间接口的EAP报文

问题:Chewie无法捕获Mininet命名空间内接口的EAP报文

我的目标

在Mininet创建的命名空间内接口上运行Chewie(Faucet的802.1X处理模块),捕获EAP报文。当前环境为Faucet SDN控制器+Mininet拓扑,Chewie作为认证器需监听NFV端口,对接RADIUS完成认证流程。

问题描述

Chewie配置监听主机侧可见的veth接口s1-eth3,但实际EAP报文被转发到Mininet命名空间内的listener-eth0接口,直接指定listener-eth0会提示设备不存在,导致Chewie无法收到报文。

已确认:

  • Chewie本身功能正常:监听lo接口时,主机侧发送EAP报文能正常响应并启动认证流程
  • 交换机转发逻辑正常:Wireshark可捕获到EAP起始报文,对应流表存在(流表会修改目的MAC为00:00:00:00:00:01后转发到s1-eth3)

主机侧接口信息:

root@ubuntu2004:~# ip link show
[...]
33: s1-eth3@if2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master ovs-system state UP mode DEFAULT group default qlen 1000
    link/ether d2:90:29:3a:15:f7 brd ff:ff:ff:ff:ff:ff link-netnsid 1

命名空间内接口信息:

mininet> listener ifconfig
listener-eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 10.0.0.2  netmask 255.0.0.0  broadcast 10.255.255.255
        inet6 fe80::2095:66ff:feab:8918  prefixlen 64  scopeid 0x20<link>
        ether 22:95:66:ab:89:18  txqueuelen 1000  (Ethernet)
        RX packets 31  bytes 3536 (3.5 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 13  bytes 1006 (1.0 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
[...]

已尝试操作

  • 监听lo接口+主机侧运行wpa_supplicant:成功收到EAP报文
  • 监听主机物理接口enp0s3(已加入Open vSwitch):失败
  • 监听Mininet创建的s1-eth3:失败

复现最小环境

Mininet拓扑代码

from mininet.topo import Topo  
  
class MyTopo(Topo):  
    "Simple topology example."  
    def build(self):  
        # Add hosts and switches  
        client = self.addHost('client')  
        server = self.addHost('server')  
        listener = self.addHost('listener')  
        switch = self.addSwitch('s1')  
  
        # Add links  
        self.addLink(client, switch)  
        self.addLink(server, switch)  
        self.addLink(listener, switch)  
  
topos = {'mytopo': (lambda: MyTopo())}

Faucet配置

vlans:
    office:
        vid: 100
        description: "office network"
    radius:
        vid: 200
        description: "radius network"

dps:
    sw1:
        dp_id: 0x1
        dot1x:
            nfv_intf: s1-eth3
            nfv_sw_port: 3
            radius_ip: 127.0.0.1
            radius_port: 18120
            radius_secret: SECRET
        hardware: "Open vSwitch"
        interfaces:
            1:
                name: "RADIUS for host 1"
                dot1x: true
                dot1x_dyn_acl: true
                native_vlan: office
            2:
                name: "host2"
                description: "host2 network namespace"
                native_vlan: office
            3:
                name: "eap listening port"
                output_only: true
acls:
    block-ping:
        - rule:
            dl_type: 0x800      # IPv4
            ip_proto: 1         # ICMP
            actions:
                allow: False
        - rule:
            dl_type: 0x86dd     # IPv6
            ip_proto: 58        # ICMPv6
            actions:
                allow: False

wpa_supplicant配置

ctrl_interface=/tmp/wpa_supplicant
ctrl_interface_group=0
ap_scan=0

network={
 key_mgmt=IEEE8021X
 eap=MD5
 identity="admin"
 password="test123"
 eapol_flags=0
}

复现步骤

  1. 启动Faucet服务:systemctl start faucet
  2. 启动Mininet拓扑:sudo mn --custom mytopo.py --topo mytopo --controller=remote
  3. 在client节点运行wpa_supplicant,查看/var/log/faucet/faucet.log是否有收到EAP报文的记录

解决方案

方案1:将Chewie移入listener命名空间(推荐)

Chewie默认在主机命名空间运行,无法访问Mininet主机的命名空间接口,需将其进程移入对应的命名空间:

  1. 停止Faucet服务:
systemctl stop faucet
  1. 获取listener命名空间名称:
ip netns identify $(pgrep -f "mininet: listener")
# 输出示例:mininet-listener
  1. 修改Faucet的systemd配置,添加命名空间参数:
    编辑/lib/systemd/system/faucet.service,在[Service]段添加:
IPNamespace=mininet-listener
  1. 更新systemd配置并重启Faucet:
systemctl daemon-reload
systemctl start faucet
  1. 修改Faucet配置中的nfv_intf为listener-eth0,然后重启Faucet生效:
dot1x:
    nfv_intf: listener-eth0
    # 其余配置保持不变

方案2:用OVS端口镜像复制流量到主机侧接口

若不想移动进程,可配置OVS将s1-eth3的流量镜像到主机侧可访问的接口,让Chewie监听该镜像接口:

  1. 配置OVS镜像规则:
ovs-vsctl -- --id=@p get port s1-eth3 -- --id=@m create mirror name=eap_mirror select-dst-port=@p output-port=enp0s3 -- set bridge s1 mirrors=@m
  1. 修改Faucet配置中的nfv_intf为enp0s3,重启Faucet生效。

方案3:修改Chewie源码支持跨命名空间监听(进阶)

参考Chewie的nfv_sockets.py代码,添加进程切换网络命名空间的逻辑:通过打开命名空间的netns文件,切换后再创建监听套接字。此方法需修改Chewie源码,适合具备开发能力的用户。


内容的提问来源于stack exchange,提问作者Filip Perz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 15:37:34