You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器中Kali Linux无法连接OpenVPN:tun接口创建失败

问题

在Docker容器内的Kali Linux环境中无法连接OpenVPN,核心报错为:

ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)

完整报错日志:

2023-11-21 14:26:21 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2023-11-21 14:26:21 Note: --data-cipher-fallback with cipher 'AES-128-CBC' disables data channel offload.
2023-11-21 14:26:21 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2023-11-21 14:26:21 library versions: OpenSSL 3.0.11 19 Sep 2023, LZO 2.10
2023-11-21 14:26:21 DCO version: N/A
2023-11-21 14:26:26 TCP/UDP: Preserving recently used remote address: [AF_INET]142.234.200.48:1337
2023-11-21 14:26:26 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-11-21 14:26:26 UDPv4 link local: (not bound)
2023-11-21 14:26:26 UDPv4 link remote: [AF_INET]142.234.200.48:1337
2023-11-21 14:26:26 TLS: Initial packet from [AF_INET]142.234.200.48:1337, sid=622ca76c 52931832
2023-11-21 14:26:26 VERIFY OK: depth=1, C=UK, ST=City, L=London, O=HackTheBox, CN=HackTheBox CA, name=htb, emailAddress=info@hackthebox.eu
2023-11-21 14:26:26 VERIFY KU OK
2023-11-21 14:26:26 Validating certificate extended key usage
2023-11-21 14:26:26 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2023-11-21 14:26:26 VERIFY EKU OK
2023-11-21 14:26:26 VERIFY OK: depth=0, C=UK, ST=City, L=London, O=HackTheBox, CN=htb, name=htb, emailAddress=info@hackthebox.eu
2023-11-21 14:26:27 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA1, peer temporary key: 253 bits X25519
2023-11-21 14:26:27 [htb] Peer Connection Initiated with [AF_INET]142.234.200.48:1337
2023-11-21 14:26:27 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
2023-11-21 14:26:27 TLS: tls_multi_process: initial untrusted session promoted to trusted
2023-11-21 14:26:27 PUSH: Received control message: 'PUSH_REPLY,route 10.10.10.0 255.255.254.0,route 10.129.0.0 255.255.0.0,route-ipv6 dead:beef::/64,tun-ipv6,route-gateway 10.10.14.1,topology subnet,ping 10,ping-restart 120,ifconfig-ipv6 dead:beef:2::109e/64 dead:beef:2::1,ifconfig 10.10.14.160 255.255.254.0,peer-id 0,cipher AES-256-CBC'
2023-11-21 14:26:27 OPTIONS IMPORT: --ifconfig/up options modified
2023-11-21 14:26:27 OPTIONS IMPORT: route options modified
2023-11-21 14:26:27 OPTIONS IMPORT: route-related options modified
2023-11-21 14:26:27 net_route_v4_best_gw query: dst 0.0.0.0
2023-11-21 14:26:27 net_route_v4_best_gw result: via 172.17.0.1 dev eth0
2023-11-21 14:26:27 ROUTE_GATEWAY 172.17.0.1/255.255.0.0 IFACE=eth0 HWADDR=02:42:ac:11:00:02
2023-11-21 14:26:27 GDG6: remote_host_ipv6=n/a
2023-11-21 14:26:27 net_route_v6_best_gw query: dst ::
2023-11-21 14:26:27 sitnl_send: rtnl: generic error (-101): Network is unreachable
2023-11-21 14:26:27 ROUTE6: default_gateway=UNDEF
2023-11-21 14:26:27 ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)
2023-11-21 14:26:27 Exiting due to fatal error

已尝试ifconfig tun0 create命令,尚未尝试在容器外通过Docker命令创建适配器。

解决方案

1. 启动容器时添加权限与设备映射

Docker容器默认无创建TUN/TAP接口的权限,启动容器时必须添加以下参数:

  • --cap-add NET_ADMIN:授予容器网络管理权限
  • --device /dev/net/tun:映射宿主机TUN设备到容器内

完整启动命令示例:

docker run -it --cap-add NET_ADMIN --device /dev/net/tun kalilinux/kali-rolling

注:已创建的容器无法直接修改权限配置,需删除后重新创建。

2. 容器内手动配置TUN设备

进入容器后,先检查/dev/net/tun是否存在:

ls -l /dev/net/tun

若不存在,执行以下命令手动创建:

mkdir -p /dev/net
mknod /dev/net/tun c 10 200
chmod 600 /dev/net/tun

完成后再启动OpenVPN。

3. 优化OpenVPN配置(可选)

若仍出现IPv6相关报错,可在OpenVPN配置文件中添加以下参数,忽略服务器推送的IPv6路由:

pull-filter ignore "route-ipv6"
pull-filter ignore "ifconfig-ipv6"

内容的提问来源于stack exchange,提问作者Derek Rickmon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 17:03:16