network:vpn:wireguard_access_ipv4_to_ipv6_tunnel
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| network:vpn:wireguard_access_ipv4_to_ipv6_tunnel [2023/08/16 00:04] – external edit (Unknown date) 127.0.0.1 | network:vpn:wireguard_access_ipv4_to_ipv6_tunnel [Unknown date] (current) – external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 11: | Line 11: | ||
| tar -xf ../ | tar -xf ../ | ||
| cp udp2raw_amd64_hw_aes /usr/bin | cp udp2raw_amd64_hw_aes /usr/bin | ||
| - | setcap | + | # This is for testing as a unpriviledged user see below |
| + | setcap | ||
| cd .. | cd .. | ||
| rm -rf udp2raw | rm -rf udp2raw | ||
| Line 27: | Line 28: | ||
| # Generate / | # Generate / | ||
| ExecStartPre=ip6tables -I INPUT -s $(MD_IPV6_PREFIX):: | ExecStartPre=ip6tables -I INPUT -s $(MD_IPV6_PREFIX):: | ||
| - | User=nobody | + | DynamicUser=yes |
| + | AmbientCapabilities=CAP_NET_BIND_SERVICE CAP_NET_RAW | ||
| ExecStart=/ | ExecStart=/ | ||
| # As root ExecStart=/ | # As root ExecStart=/ | ||
| ExecReload=/ | ExecReload=/ | ||
| - | ExecStop=/ | + | ExecStop=/ |
| + | PrivateTmp=true | ||
| Restart=always | Restart=always | ||
| [Install] | [Install] | ||
network/vpn/wireguard_access_ipv4_to_ipv6_tunnel.1692137059.txt.gz · Last modified: by 127.0.0.1