gluetun
gluetun copied to clipboard
Bug: openvpn `ip -6 addr` and error `RTNETLINK answers: Permission denied`
Is this urgent?
No
Host OS
Synology DSM 7.1.1
CPU arch
x86_64
VPN service provider
PrivateVPN
What are you using to run the container
Portainer
What is the version of Gluetun
Running version latest built on 2024-08-25T07:04:32.409Z (commit 01fa993)
What's the problem π€
Since a few hours my gluetun is unable to connect to my VPN provider (Perfect Privacy, not available in form Dropdown!!!). FAQ healthcheck and update provider list have been checked and done already. Update seems to be successful as per βlast editedβ of that json file on host.
Seems related to RTNETLINK issue as per the logs. Unsure on how to solve this
Share your logs (at least 10 lines)
========================================
========================================
=============== gluetun ================
========================================
=========== Made with β€οΈ by ============
======= https://github.com/qdm12 =======
========================================
========================================
Running version latest built on 2024-08-25T07:04:32.409Z (commit 01fa993)
π§ Need help? β Discussion? https://github.com/qdm12/gluetun/discussions/new/choose
π Bug? β¨ New feature? https://github.com/qdm12/gluetun/issues/new/choose
π» Email? [email protected]
π° Help me? https://www.paypal.me/qmcgaw https://github.com/sponsors/qdm12
2024-08-31T13:18:37+02:00 INFO [routing] default route found: interface eth0, gateway 172.17.0.1, assigned IP 172.17.0.8 and family v4
2024-08-31T13:18:37+02:00 INFO [routing] local ethernet link found: eth0
2024-08-31T13:18:37+02:00 INFO [routing] local ipnet found: 172.17.0.0/16
2024-08-31T13:18:37+02:00 INFO [firewall] enabling...
2024-08-31T13:18:37+02:00 INFO [firewall] enabled successfully
2024-08-31T13:18:38+02:00 INFO [storage] merging by most recent 20480 hardcoded servers and 20475 servers read from /gluetun/servers.json
2024-08-31T13:18:38+02:00 INFO [storage] Using perfect privacy servers from file which are 498 days more recent
2024-08-31T13:18:39+02:00 INFO Alpine version: 3.20.2
2024-08-31T13:18:39+02:00 INFO OpenVPN 2.5 version: 2.5.10
2024-08-31T13:18:39+02:00 INFO OpenVPN 2.6 version: 2.6.11
2024-08-31T13:18:39+02:00 INFO IPtables version: v1.8.10
2024-08-31T13:18:39+02:00 INFO Settings summary:
βββ VPN settings:
| βββ VPN provider settings:
| | βββ Name: perfect privacy
| | βββ Server selection settings:
| | βββ VPN type: openvpn
| | βββ Cities: Amsterdam
| | βββ OpenVPN server selection settings:
| | βββ Protocol: UDP
| βββ OpenVPN settings:
| βββ OpenVPN version: 2.6
| βββ User: [set]
| βββ Password: [set]
| βββ Network interface: tun0
| βββ Run OpenVPN as: root
| βββ Verbosity level: 1
βββ DNS settings:
| βββ Keep existing nameserver(s): no
| βββ DNS server address to use: 127.0.0.1
| βββ DNS over TLS settings:
| βββ Enabled: yes
| βββ Update period: every 24h0m0s
| βββ Upstream resolvers:
| | βββ cloudflare
| βββ Caching: yes
| βββ IPv6: no
| βββ DNS filtering settings:
| βββ Block malicious: yes
| βββ Block ads: no
| βββ Block surveillance: no
| βββ Blocked IP networks:
| βββ 127.0.0.1/8
| βββ 10.0.0.0/8
| βββ 172.16.0.0/12
| βββ 192.168.0.0/16
| βββ 169.254.0.0/16
| βββ ::1/128
| βββ fc00::/7
| βββ fe80::/10
| βββ ::ffff:127.0.0.1/104
| βββ ::ffff:10.0.0.0/104
| βββ ::ffff:169.254.0.0/112
| βββ ::ffff:172.16.0.0/108
| βββ ::ffff:192.168.0.0/112
βββ Firewall settings:
| βββ Enabled: yes
βββ Log settings:
| βββ Log level: info
βββ Health settings:
| βββ Server listening address: 127.0.0.1:9999
| βββ Target address: cloudflare.com:443
| βββ Duration to wait after success: 5s
| βββ Read header timeout: 100ms
| βββ Read timeout: 500ms
| βββ VPN wait durations:
| βββ Initial duration: 6s
| βββ Additional duration: 5s
βββ Shadowsocks server settings:
| βββ Enabled: no
βββ HTTP proxy settings:
| βββ Enabled: no
βββ Control server settings:
| βββ Listening address: :8000
| βββ Logging: yes
βββ Storage settings:
| βββ Filepath: /gluetun/servers.json
βββ OS Alpine settings:
| βββ Process UID: 1000
| βββ Process GID: 1000
| βββ Timezone: Europe/Berlin
βββ Public IP settings:
| βββ Fetching: every 12h0m0s
| βββ IP file path: /tmp/gluetun/ip
| βββ Public IP data API: ipinfo
βββ Server data updater settings:
| βββ Update period: 24h0m0s
| βββ DNS address: 1.1.1.1:53
| βββ Minimum ratio: 0.8
| βββ Providers to update: perfect privacy
βββ Version settings:
βββ Enabled: yes
2024-08-31T13:18:39+02:00 INFO [routing] default route found: interface eth0, gateway 172.17.0.1, assigned IP 172.17.0.8 and family v4
2024-08-31T13:18:39+02:00 INFO [routing] adding route for 0.0.0.0/0
2024-08-31T13:18:39+02:00 INFO [firewall] setting allowed subnets...
2024-08-31T13:18:39+02:00 INFO [routing] default route found: interface eth0, gateway 172.17.0.1, assigned IP 172.17.0.8 and family v4
2024-08-31T13:18:39+02:00 INFO TUN device is not available: open /dev/net/tun: no such file or directory; creating it...
2024-08-31T13:18:39+02:00 INFO [dns] using plaintext DNS at address 1.1.1.1
2024-08-31T13:18:39+02:00 INFO [http server] http server listening on [::]:8000
2024-08-31T13:18:39+02:00 INFO [healthcheck] listening on 127.0.0.1:9999
2024-08-31T13:18:39+02:00 INFO [firewall] allowing VPN connection...
2024-08-31T13:18:39+02:00 INFO [openvpn] OpenVPN 2.6.11 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2024-08-31T13:18:39+02:00 INFO [openvpn] library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-08-31T13:18:39+02:00 WARN [openvpn] No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2024-08-31T13:18:39+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]95.211.95.233:443
2024-08-31T13:18:39+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2024-08-31T13:18:39+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]95.211.95.233:443
2024-08-31T13:18:39+02:00 INFO [openvpn] [Server_amsterdam.perfect-privacy.com] Peer Connection Initiated with [AF_INET]95.211.95.233:443
2024-08-31T13:18:40+02:00 INFO [openvpn] TUN/TAP device tun0 opened
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip addr add dev tun0 10.0.51.248/24
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:18:40+02:00 INFO [openvpn] /sbin/ip -6 addr add fdbf:1d37:bbe0:0:3:3:0:f8/112 dev tun0
2024-08-31T13:18:40+02:00 ERROR [openvpn] RTNETLINK answers: Permission denied
2024-08-31T13:18:40+02:00 INFO [openvpn] Linux ip -6 addr add failed: external program exited with error status: 2
2024-08-31T13:18:40+02:00 INFO [openvpn] Exiting due to fatal error
2024-08-31T13:18:40+02:00 ERROR [vpn] exit status 1
2024-08-31T13:18:40+02:00 INFO [vpn] retrying in 15s
2024-08-31T13:18:45+02:00 INFO [healthcheck] program has been unhealthy for 6s: restarting VPN
2024-08-31T13:18:45+02:00 INFO [healthcheck] π See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md
2024-08-31T13:18:45+02:00 INFO [healthcheck] DO NOT OPEN AN ISSUE UNLESS YOU READ AND TRIED EACH POSSIBLE SOLUTION
2024-08-31T13:18:55+02:00 INFO [firewall] allowing VPN connection...
2024-08-31T13:18:55+02:00 INFO [openvpn] OpenVPN 2.6.11 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2024-08-31T13:18:55+02:00 INFO [openvpn] library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-08-31T13:18:55+02:00 WARN [openvpn] No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2024-08-31T13:18:55+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]95.168.167.236:443
2024-08-31T13:18:55+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2024-08-31T13:18:55+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]95.168.167.236:443
2024-08-31T13:18:55+02:00 INFO [openvpn] [Server_amsterdam.perfect-privacy.com] Peer Connection Initiated with [AF_INET]95.168.167.236:443
2024-08-31T13:18:56+02:00 INFO [openvpn] TUN/TAP device tun0 opened
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip addr add dev tun0 10.5.209.64/24
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:18:56+02:00 INFO [openvpn] /sbin/ip -6 addr add fdbf:1d37:bbe0:0:93:1:0:40/112 dev tun0
2024-08-31T13:18:56+02:00 ERROR [openvpn] RTNETLINK answers: Permission denied
2024-08-31T13:18:56+02:00 INFO [openvpn] Linux ip -6 addr add failed: external program exited with error status: 2
2024-08-31T13:18:56+02:00 INFO [openvpn] Exiting due to fatal error
2024-08-31T13:18:56+02:00 ERROR [vpn] exit status 1
2024-08-31T13:18:56+02:00 INFO [vpn] retrying in 15s
2024-08-31T13:19:06+02:00 INFO [healthcheck] program has been unhealthy for 11s: restarting VPN
2024-08-31T13:19:06+02:00 INFO [healthcheck] π See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md
2024-08-31T13:19:06+02:00 INFO [healthcheck] DO NOT OPEN AN ISSUE UNLESS YOU READ AND TRIED EACH POSSIBLE SOLUTION
2024-08-31T13:19:11+02:00 INFO [firewall] allowing VPN connection...
2024-08-31T13:19:11+02:00 INFO [openvpn] OpenVPN 2.6.11 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2024-08-31T13:19:11+02:00 INFO [openvpn] library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-08-31T13:19:11+02:00 WARN [openvpn] No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2024-08-31T13:19:11+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]37.48.94.1:443
2024-08-31T13:19:11+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2024-08-31T13:19:11+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]37.48.94.1:443
2024-08-31T13:19:27+02:00 INFO [healthcheck] program has been unhealthy for 16s: restarting VPN
2024-08-31T13:19:27+02:00 INFO [healthcheck] π See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md
2024-08-31T13:19:27+02:00 INFO [healthcheck] DO NOT OPEN AN ISSUE UNLESS YOU READ AND TRIED EACH POSSIBLE SOLUTION
2024-08-31T13:19:27+02:00 INFO [vpn] stopping
2024-08-31T13:19:27+02:00 INFO [vpn] starting
2024-08-31T13:19:27+02:00 INFO [firewall] allowing VPN connection...
2024-08-31T13:19:27+02:00 INFO [openvpn] OpenVPN 2.6.11 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2024-08-31T13:19:27+02:00 INFO [openvpn] library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-08-31T13:19:27+02:00 WARN [openvpn] No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2024-08-31T13:19:27+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]95.168.167.236:443
2024-08-31T13:19:27+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2024-08-31T13:19:27+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]95.168.167.236:443
2024-08-31T13:19:27+02:00 INFO [openvpn] [Server_amsterdam.perfect-privacy.com] Peer Connection Initiated with [AF_INET]95.168.167.236:443
2024-08-31T13:19:27+02:00 INFO [openvpn] TUN/TAP device tun0 opened
2024-08-31T13:19:27+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:19:28+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:19:28+02:00 INFO [openvpn] /sbin/ip addr add dev tun0 10.5.209.73/24
2024-08-31T13:19:28+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:19:28+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:19:28+02:00 INFO [openvpn] /sbin/ip -6 addr add fdbf:1d37:bbe0:0:93:1:0:49/112 dev tun0
2024-08-31T13:19:28+02:00 INFO [openvpn] Linux ip -6 addr add failed: external program exited with error status: 2
2024-08-31T13:19:28+02:00 ERROR [openvpn] RTNETLINK answers: Permission denied
2024-08-31T13:19:28+02:00 INFO [openvpn] Exiting due to fatal error
2024-08-31T13:19:28+02:00 ERROR [vpn] exit status 1
2024-08-31T13:19:28+02:00 INFO [vpn] retrying in 15s
2024-08-31T13:19:43+02:00 INFO [firewall] allowing VPN connection...
2024-08-31T13:19:43+02:00 INFO [openvpn] OpenVPN 2.6.11 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2024-08-31T13:19:43+02:00 INFO [openvpn] library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-08-31T13:19:43+02:00 WARN [openvpn] No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2024-08-31T13:19:43+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]95.211.95.244:443
2024-08-31T13:19:43+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2024-08-31T13:19:43+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]95.211.95.244:443
2024-08-31T13:19:43+02:00 INFO [openvpn] [Server_amsterdam.perfect-privacy.com] Peer Connection Initiated with [AF_INET]95.211.95.244:443
2024-08-31T13:19:44+02:00 INFO [openvpn] TUN/TAP device tun0 opened
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip addr add dev tun0 10.0.64.50/24
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2024-08-31T13:19:44+02:00 INFO [openvpn] /sbin/ip -6 addr add fdbf:1d37:bbe0:0:4::32/112 dev tun0
2024-08-31T13:19:44+02:00 ERROR [openvpn] RTNETLINK answers: Permission denied
2024-08-31T13:19:44+02:00 INFO [openvpn] Linux ip -6 addr add failed: external program exited with error status: 2
2024-08-31T13:19:44+02:00 INFO [openvpn] Exiting due to fatal error
2024-08-31T13:19:44+02:00 ERROR [vpn] exit status 1
2024-08-31T13:19:44+02:00 INFO [vpn] retrying in 15s
2024-08-31T13:19:48+02:00 INFO [healthcheck] program has been unhealthy for 21s: restarting VPN
2024-08-31T13:19:48+02:00 INFO [healthcheck] π See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md
2024-08-31T13:19:48+02:00 INFO [healthcheck] DO NOT OPEN AN ISSUE UNLESS YOU READ AND TRIED EACH POSSIBLE SOLUTION
Share your configuration
version: "3.8"
services:
gluetun:
image: qmcgaw/gluetun
container_name: gluetun
cap_add:
- NET_ADMIN
ports:
- 8888:8888/tcp # HTTP proxy
- 8388:8388/tcp # Shadowsocks
- 8388:8388/udp # Shadowsocks
- 8090:8090 # port for app web ui
- 6881:6881 # port for app data
volumes:
- /volume/for/container/configs/gluetun:/gluetun
environment:
- VPN_SERVICE_PROVIDER=perfect privacy
- VPN_TYPE=openvpn
- OPENVPN_USER=redacted-user
- OPENVPN_PASSWORD=redacted-password
- SERVER_CITIES=Amsterdam
- UPDATER_PERIOD=24h # update provider list
- UPDATER_VPN_SERVICE_PROVIDERS=perfect privacy
- TZ=Europe/Berlin
network_mode: bridge
restart: always
# privileged: true
# devices:
# - /dev/net/tun:/dev/net/tun
# command: update -enduser -providers "perfect privacy" # Force update of list