OpenSnitch in Debian ready for prime time
people.skolelinux.org
people.skolelinux.org
and for TFA, that's also nice. and i think, if it works on debian, it could be made work on vast majority of other distros.
I predict in the coming years the sorts of invasive surveillance capitalism we see today will in most cases become too economically unviable to be considered worthwhile outside a handful of closed ecosystems.
ip netns add torrent
ip link add wg1 type wireguard
ip link set wg1 netns torrent
ip -n torrent addr add 10.67.124.111/32 dev wg1
ip netns exec torrent wg setconf wg1 /etc/wireguard/wg1.conf
ip -n torrent link set wg1 up
ip -n torrent route add default dev wg1
ip netns exec torrent ip link set dev lo up
ip netns exec torrent transmission-daemon -f 2>&1
AFAIK it's pretty bulletproof. But for good measure I also have transmission configured to only listen on the wireguard address.Is there a tool out there to manage these namespaces automatically? I'd like to isolate applications from each other or put them in groups together, but I really don't want to deal with writing scripts for every single application.
I have read that some use NetworkManager by running a whole separate instance of it in their netns, along with a a D-Bus broker running in there too for clients to communicate with NM.
automation indeed sucks
I ended up writing a shell script to handle setting up a bridge, launching the container with systemd-nspawn and kick off commands to bring up the virtual ethernet interfaces inside the container and handle some other housekeeping
systemd-nspawn with systemd-network/resolve/etc can automatically manage the IP addresses for you. I'm using it as a wrapper around cgroup/netns commands.
One of these days, I will remove the dependency on systemd-nspawn so that I can use it on Linux systems without systemd or docker.
I keep all my routing complexity contained to one (virtual) machine with extensive nftables rules, that functions as the house router. It has a table with each host and the network horizon it can see. Then I create a virtual machine for each activity that needs a separate horizon.
The one thing I'm missing is some way of securing the binding of hosts to addresses. Most switches/devices don't support ethernet authentication. I could do something like fine grained VLANs and keeping track of what is connected to what, but that seems like a huge pain in the ass.
ability to filter by incoming port and process ID combined. This is a Linux netfilter limitation.
Considering Process ID almost always changes, is that a significant limitation? I can think of one use case when it can be useful is when you want to apply the rule temporarily until the process is restarted.
Most of this kind of firewall rule get created after such executable starts ... by a dedicated firewall daemon monitoring the operating system's PID state (creation/deletion/child).
I look forward to this landing so it will eventually appear in the downstream distro I use.
This the kind of work Ubuntu should be sponsoring.
If so, it "is currently not available for macOS". https://docs.safing.io/portmaster/install/status/mac