Opened 3 years ago

Last modified 2 months ago

#556 new Feature Wish

Dual Stack: bind to multiple IPv4 and IPv6 addresses not working

Reported by: crane Owned by:
Priority: major Milestone: release 2.5
Component: IPv6 Version: OpenVPN git master branch (Community Ed)
Severity: Not set (select this one, unless your'e a OpenVPN developer) Keywords: ipv6 ipv4 dualstack
Cc: plaisthos, Heiko Hund

Description

Hi,

it looks like it is not possible not bind OpenVPN in dual stack mode on specific IPs.

If I run the server plain with udp6 he is listening on all interfaces (v4 and v6). Now I would like to restrict this to a few interfaces. But in dual stack mode an IPv4 adress in local causes the server to crash:

[openvpn.log]
Mon May 18 12:02:48 2015 us=69753 OpenVPN 2.3.4 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [MH] [IPv6] built on Dec 1 2014
Mon May 18 12:02:48 2015 us=69765 library versions: OpenSSL 1.0.1k 8 Jan 2015, LZO 2.08
Mon May 18 12:02:48 2015 us=73425 Diffie-Hellman initialized with 2048 bit key
Mon May 18 12:02:48 2015 us=73603 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon May 18 12:02:48 2015 us=73614 Socket Buffers: R=[212992->131072] S=[212992->131072]
Mon May 18 12:02:48 2015 us=73619 RESOLVE: Cannot resolve host address: 10.20.30.40: Address family for hostname not supported
Mon May 18 12:02:48 2015 us=73623 Exiting due to fatal error

Either the option should support both or there should be a specific option like this:
local 10.20.30.40
local6 fe80::fc54:ff:fe54:7933

Change History (4)

comment:1 Changed 3 years ago by Gert Döring

Cc: plaisthos added
Milestone: release 2.4
Type: Bug / DefectFeature Wish
Version: 2.3.4git master branch

If you want to bind to an IPv4 address, do not use "proto udp6"... and no, you cannot currently bind to multiple specific IPv4 and/or IPv6 addresses at the same time, it's either "one!" or "all of them". Sorry.

(Feel free to contribute patches to git master, but this stuff is actually amazingly complicated, so it won't go into 2.3 no matter what - it's on our radar since quite a while, but "complicated")

comment:2 Changed 3 years ago by Gert Döring

Summary: Dual Stack with specific IPv4 not workingDual Stack: bind to multiple IPv4 and IPv6 addresses not working

changing the subject to make clear that this is not about "dual-stack *inside* the tunnel" (where we have a similar-sounding issue with "--ifconfig-push" and "ifconfig-pool-ipv6" :-) )

comment:3 Changed 22 months ago by Gert Döring

Cc: Heiko Hund added
Milestone: release 2.4release 2.5

This is not going to make 2.4 in time (due in a few weeks).

Bumping to milestone release 2.5 - d12fk is working on multi-socket listening, but it's not complete and won't make it.

comment:4 Changed 2 months ago by Antonio

For the records: a first RFC patchset has been sent to the mailing list:
https://sourceforge.net/p/openvpn/mailman/openvpn-devel/thread/20180425195722.20744-1-a@unstable.cc/

This patchset enables OpenVPN to listen on multiple sockets.
Each socket can have its own IP and port (and IPs can be of different families).

Tests/reviews/feedback are higly appreciated!

Note: See TracTickets for help on using tickets.