Docker容器中Kali Linux无法连接OpenVPN:tun接口创建失败
问题
在Docker容器内的Kali Linux环境中无法连接OpenVPN,核心报错为:
ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)
完整报错日志:
2023-11-21 14:26:21 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set. 2023-11-21 14:26:21 Note: --data-cipher-fallback with cipher 'AES-128-CBC' disables data channel offload. 2023-11-21 14:26:21 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] 2023-11-21 14:26:21 library versions: OpenSSL 3.0.11 19 Sep 2023, LZO 2.10 2023-11-21 14:26:21 DCO version: N/A 2023-11-21 14:26:26 TCP/UDP: Preserving recently used remote address: [AF_INET]142.234.200.48:1337 2023-11-21 14:26:26 Socket Buffers: R=[212992->212992] S=[212992->212992] 2023-11-21 14:26:26 UDPv4 link local: (not bound) 2023-11-21 14:26:26 UDPv4 link remote: [AF_INET]142.234.200.48:1337 2023-11-21 14:26:26 TLS: Initial packet from [AF_INET]142.234.200.48:1337, sid=622ca76c 52931832 2023-11-21 14:26:26 VERIFY OK: depth=1, C=UK, ST=City, L=London, O=HackTheBox, CN=HackTheBox CA, name=htb, emailAddress=info@hackthebox.eu 2023-11-21 14:26:26 VERIFY KU OK 2023-11-21 14:26:26 Validating certificate extended key usage 2023-11-21 14:26:26 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication 2023-11-21 14:26:26 VERIFY EKU OK 2023-11-21 14:26:26 VERIFY OK: depth=0, C=UK, ST=City, L=London, O=HackTheBox, CN=htb, name=htb, emailAddress=info@hackthebox.eu 2023-11-21 14:26:27 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA1, peer temporary key: 253 bits X25519 2023-11-21 14:26:27 [htb] Peer Connection Initiated with [AF_INET]142.234.200.48:1337 2023-11-21 14:26:27 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1 2023-11-21 14:26:27 TLS: tls_multi_process: initial untrusted session promoted to trusted 2023-11-21 14:26:27 PUSH: Received control message: 'PUSH_REPLY,route 10.10.10.0 255.255.254.0,route 10.129.0.0 255.255.0.0,route-ipv6 dead:beef::/64,tun-ipv6,route-gateway 10.10.14.1,topology subnet,ping 10,ping-restart 120,ifconfig-ipv6 dead:beef:2::109e/64 dead:beef:2::1,ifconfig 10.10.14.160 255.255.254.0,peer-id 0,cipher AES-256-CBC' 2023-11-21 14:26:27 OPTIONS IMPORT: --ifconfig/up options modified 2023-11-21 14:26:27 OPTIONS IMPORT: route options modified 2023-11-21 14:26:27 OPTIONS IMPORT: route-related options modified 2023-11-21 14:26:27 net_route_v4_best_gw query: dst 0.0.0.0 2023-11-21 14:26:27 net_route_v4_best_gw result: via 172.17.0.1 dev eth0 2023-11-21 14:26:27 ROUTE_GATEWAY 172.17.0.1/255.255.0.0 IFACE=eth0 HWADDR=02:42:ac:11:00:02 2023-11-21 14:26:27 GDG6: remote_host_ipv6=n/a 2023-11-21 14:26:27 net_route_v6_best_gw query: dst :: 2023-11-21 14:26:27 sitnl_send: rtnl: generic error (-101): Network is unreachable 2023-11-21 14:26:27 ROUTE6: default_gateway=UNDEF 2023-11-21 14:26:27 ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1) 2023-11-21 14:26:27 Exiting due to fatal error
已尝试ifconfig tun0 create命令,尚未尝试在容器外通过Docker命令创建适配器。
解决方案
1. 启动容器时添加权限与设备映射
Docker容器默认无创建TUN/TAP接口的权限,启动容器时必须添加以下参数:
--cap-add NET_ADMIN:授予容器网络管理权限--device /dev/net/tun:映射宿主机TUN设备到容器内
完整启动命令示例:
docker run -it --cap-add NET_ADMIN --device /dev/net/tun kalilinux/kali-rolling
注:已创建的容器无法直接修改权限配置,需删除后重新创建。
2. 容器内手动配置TUN设备
进入容器后,先检查/dev/net/tun是否存在:
ls -l /dev/net/tun
若不存在,执行以下命令手动创建:
mkdir -p /dev/net mknod /dev/net/tun c 10 200 chmod 600 /dev/net/tun
完成后再启动OpenVPN。
3. 优化OpenVPN配置(可选)
若仍出现IPv6相关报错,可在OpenVPN配置文件中添加以下参数,忽略服务器推送的IPv6路由:
pull-filter ignore "route-ipv6" pull-filter ignore "ifconfig-ipv6"
内容的提问来源于stack exchange,提问作者Derek Rickmon
相关产品推荐
相关产品推荐

