#linuxnetworking — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #linuxnetworking, aggregated by home.social.
-
Today I removed some netns with various virtual interfaces. In one of the netns there was a wireguard tunnel and it looks like it is still alive.
The peer gets handshakes while I cannot find the wg in any named netns. But the "lsns --type=net" shows three namespaces without a pid and without a mount… and I assume that there is a #FrankenGuard hiding in one of them. 🧟 🧟 🧟
Any idea how I could get into these anonymous netns to remove the wg interface?
-
Today I removed some netns with various virtual interfaces. In one of the netns there was a wireguard tunnel and it looks like it is still alive.
The peer gets handshakes while I cannot find the wg in any named netns. But the "lsns --type=net" shows three namespaces without a pid and without a mount… and I assume that there is a #FrankenGuard hiding in one of them. 🧟 🧟 🧟
Any idea how I could get into these anonymous netns to remove the wg interface?
-
…a ping to the management ip got a dest unreachable. 🤯
*WTF*
Need to crash it just another time to have a serial console logging ready: https://tpaste.us/VnYv
It initial happened on 6.18.33 with 1Gbps/140k pps forwarding traffic, but also on 6.18.35 with some lower throughput. 😭
The XDP program can be found at https://codeberg.org/routerkit/fragg-off - it might crash your machine 🤷
What a day!
(2/2)
-
…a ping to the management ip got a dest unreachable. 🤯
*WTF*
Need to crash it just another time to have a serial console logging ready: https://tpaste.us/VnYv
It initial happened on 6.18.33 with 1Gbps/140k pps forwarding traffic, but also on 6.18.35 with some lower throughput. 😭
The XDP program can be found at https://codeberg.org/routerkit/fragg-off - it might crash your machine 🤷
What a day!
(2/2)
-
Last week I participated #SaltSprint to discuss declarative network configuration in #NixOS. I got the feedback, that replacing scripted networking with #ifstate of a full blown frr-based EVPN setup is possible and did just work. 💪
This feedback makes me really happy 🤗 #WorksAsIntended
In return, ifstate got a larger pull request improving its python packaging and CI tooling. And there is a commitment for further contributions. ❤️ ❤️ ❤️
https://github.com/NixOS/nixpkgs/issues/287308#issuecomment-4800845326
-
Last week I participated #SaltSprint to discuss declarative network configuration in #NixOS. I got the feedback, that replacing scripted networking with #ifstate of a full blown frr-based EVPN setup is possible and did just work. 💪
This feedback makes me really happy 🤗 #WorksAsIntended
In return, ifstate got a larger pull request improving its python packaging and CI tooling. And there is a commitment for further contributions. ❤️ ❤️ ❤️
https://github.com/NixOS/nixpkgs/issues/287308#issuecomment-4800845326
-
Learn how to install and configure ProxyChains on Linux. Set up chain types, enable DNS proxying, and route curl, nmap, and SSH through Tor in minutes.
Full guide here: https://ostechnix.com/install-configure-proxychains-linux/
#Proxychains #Proxy #DNS #Tor #Socks5 #LinuxNetworking #Linuxhowto
-
Learn how to install and configure ProxyChains on Linux. Set up chain types, enable DNS proxying, and route curl, nmap, and SSH through Tor in minutes.
Full guide here: https://ostechnix.com/install-configure-proxychains-linux/
#Proxychains #Proxy #DNS #Tor #Socks5 #LinuxNetworking #Linuxhowto
-
Learn essential Nmap commands for network scanning, port discovery, and OS detection. Complete guide with examples and a cheat sheet.
Full guide here: https://ostechnix.com/nmap-commands-beginners-guide/
#Nmap #NetworkMapper #Linux #LinuxNetworking #Cybersecurity #NetworkScanner #PortScanning #NetworkSecurity
-
Learn essential Nmap commands for network scanning, port discovery, and OS detection. Complete guide with examples and a cheat sheet.
Full guide here: https://ostechnix.com/nmap-commands-beginners-guide/
#Nmap #NetworkMapper #Linux #LinuxNetworking #Cybersecurity #NetworkScanner #PortScanning #NetworkSecurity
-
ifstate 2.4.1 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.4.1This release primarily fixes bugs just discovered by users upgrading to the 2.4 release. It is already available in Alpine Linux 3.24.
-
ifstate 2.4.1 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.4.1This release primarily fixes bugs just discovered by users upgrading to the 2.4 release. It is already available in Alpine Linux 3.24.
-
Learn the differences between static, transient, and temporary hostnames in Linux. Understand when to use each type and how to manage them.
Step-by-Step Guide: https://ostechnix.com/linux-hostname-types-explained-static-vs-transient-vs-temporary/
#Hostname #LinuxNetworking #Linuxcommands #Linuxhowto #Linuxadmin #Linuxbasics #Linux
-
Learn the differences between static, transient, and temporary hostnames in Linux. Understand when to use each type and how to manage them.
Step-by-Step Guide: https://ostechnix.com/linux-hostname-types-explained-static-vs-transient-vs-temporary/
#Hostname #LinuxNetworking #Linuxcommands #Linuxhowto #Linuxadmin #Linuxbasics #Linux
-
…
2) IPv6 tokenized interface identifier support was added to allow to configure the IPv6 interface identifier for interfaces doing SLAAC: https://ifstate.net/schema/2.4/#interfaces_pattern1_token
This was specified in https://datatracker.ietf.org/doc/html/draft-chown-6man-tokenised-ipv6-identifiers-02 and is implemented in the Linux kernel. Ifstate provides the same functionality as the ip-token(8) command from iproute2.
The new release is already available in Alpine Linux edge and will be part of Alpine Linux 3.24 🥳
-
…
2) IPv6 tokenized interface identifier support was added to allow to configure the IPv6 interface identifier for interfaces doing SLAAC: https://ifstate.net/schema/2.4/#interfaces_pattern1_token
This was specified in https://datatracker.ietf.org/doc/html/draft-chown-6man-tokenised-ipv6-identifiers-02 and is implemented in the Linux kernel. Ifstate provides the same functionality as the ip-token(8) command from iproute2.
The new release is already available in Alpine Linux edge and will be part of Alpine Linux 3.24 🥳
-
In case you bother why I'm looking at MAC address handling for various link types of the Linux kernel: I'm working on a new ifstate feature to get reproducible mac addresses for virtual interfaces and reset the mac address of physical links to their permanent mac address by default.
https://codeberg.org/routerkit/ifstate/pulls/185
The reproducible MAC addresses are based on SHAKE256 with an input build from the host (machine-id), netns and interface (link) name.
-
In case you bother why I'm looking at MAC address handling for various link types of the Linux kernel: I'm working on a new ifstate feature to get reproducible mac addresses for virtual interfaces and reset the mac address of physical links to their permanent mac address by default.
https://codeberg.org/routerkit/ifstate/pulls/185
The reproducible MAC addresses are based on SHAKE256 with an input build from the host (machine-id), netns and interface (link) name.
-
#TIL One could change the mac address of the lo interface, but one cannot revert it to 00:00:00:00:00:00. When the kernel boots or a netns is created, the lo interface spawns with the initial mac address 00:00:00:00:00:00. It can be changed afterwards, but it seems to be impossible to change it back to it's initial value 00:00:00:00:00:00. Fascinating. 🤷
-
#TIL One could change the mac address of the lo interface, but one cannot revert it to 00:00:00:00:00:00. When the kernel boots or a netns is created, the lo interface spawns with the initial mac address 00:00:00:00:00:00. It can be changed afterwards, but it seems to be impossible to change it back to it's initial value 00:00:00:00:00:00. Fascinating. 🤷
-
The JSON schema and it's description were missing for ifstate 2.3. It has now been published at https://ifstate.net/schema/2.3/
For your convenience the JSON Schema Store catalog entry has also been updated: https://github.com/SchemaStore/schemastore/commit/5c25db922a4928959b12fabdb6507638a2571a2d
-
The JSON schema and it's description were missing for ifstate 2.3. It has now been published at https://ifstate.net/schema/2.3/
For your convenience the JSON Schema Store catalog entry has also been updated: https://github.com/SchemaStore/schemastore/commit/5c25db922a4928959b12fabdb6507638a2571a2d
-
ifstate 2.3.0 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.3.0This is release contains various new features like:
- bridge: VLAN membership for bridge ports
- link: support external created veth ifaces
- routing: ignore routes by ifname regex
- tc: add vlan action (allows remapping); improve change detectionThe new release is already available in #AlpineLinux and in the RouterKit Debian package repository.
-
ifstate 2.3.0 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.3.0This is release contains various new features like:
- bridge: VLAN membership for bridge ports
- link: support external created veth ifaces
- routing: ignore routes by ifname regex
- tc: add vlan action (allows remapping); improve change detectionThe new release is already available in #AlpineLinux and in the RouterKit Debian package repository.
-
ifstate 2.2.6 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.2.6This is a bug-fix only release:
- fix MTU configuration for newly created tun links
- fix exception if wireguard sockets cannot be opened (i.e. due to missing kernel modules)The new release is already available in #AlpineLinux and in the RouterKit Debian package repository.
-
ifstate 2.2.6 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.2.6This is a bug-fix only release:
- fix MTU configuration for newly created tun links
- fix exception if wireguard sockets cannot be opened (i.e. due to missing kernel modules)The new release is already available in #AlpineLinux and in the RouterKit Debian package repository.
-
Building Ubuntu LTS packages for #ifstate has been enabled in git HEAD. There are pre-release builds available for Ubuntu noble and jammy.
https://codeberg.org/routerkit/-/packages/debian/ifstate/2.3.0~pre2-1
Please be aware that the next (pre-)release packages will get a conflicts to netplan.
/cc @bebehei
-
Building Ubuntu LTS packages for #ifstate has been enabled in git HEAD. There are pre-release builds available for Ubuntu noble and jammy.
https://codeberg.org/routerkit/-/packages/debian/ifstate/2.3.0~pre2-1
Please be aware that the next (pre-)release packages will get a conflicts to netplan.
/cc @bebehei
-
ifstate 2.2.5 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.2.5The 76th release includes various fixes & improvements like:
- fixing address scope handling
- fixing non-wireless interfaces handled as wireless interfaces when moving them between netns
- make parsing route table files more compatible to iproute2I am very grateful for the growing number of contributors. 🙏
-
ifstate 2.2.5 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/routerkit/ifstate/releases/tag/2.2.5The 76th release includes various fixes & improvements like:
- fixing address scope handling
- fixing non-wireless interfaces handled as wireless interfaces when moving them between netns
- make parsing route table files more compatible to iproute2I am very grateful for the growing number of contributors. 🙏
-
Okay, this is weird.
I am seeing `tailscaled` spiking up to 250% CPU usage every other minute, with up to 60 MBit/s outgoing traffic on the `tailscale0` interface... and on the `wg0` interface I see the same amount of traffic during that period.
I now disabled wireguard and the issue is gone.
But I have absolutely NO idea why this is happening, what causes it, and why it (seemingly) suddenly started - I did not have this issue earlier today. All I did in between was update the unstable channel, but all packages involved here (tailscale, wireguard) are from stable. So... 🤔 I am at loss...
#tailscale #wireguard #linux #linuxnetworking #networking #sysadmin #nixos
-
Okay, this is weird.
I am seeing `tailscaled` spiking up to 250% CPU usage every other minute, with up to 60 MBit/s outgoing traffic on the `tailscale0` interface... and on the `wg0` interface I see the same amount of traffic during that period.
I now disabled wireguard and the issue is gone.
But I have absolutely NO idea why this is happening, what causes it, and why it (seemingly) suddenly started - I did not have this issue earlier today. All I did in between was update the unstable channel, but all packages involved here (tailscale, wireguard) are from stable. So... 🤔 I am at loss...
#tailscale #wireguard #linux #linuxnetworking #networking #sysadmin #nixos
-
Unser @dd_ix Workshop zum Thema BGP Routing wurde auf den @clt_news angenommen 💪 . Für alle die meine Vorträge der letzten Jahre über Alpine Linux, ifstate oder Linux Router interessant fanden bietet sich hier die Möglichkeit für praktische Erfahrungen und Austausch.
https://chemnitzer.linux-tage.de/2026/de/programm/beitrag/329
-
Unser @dd_ix Workshop zum Thema BGP Routing wurde auf den @clt_news angenommen 💪 . Für alle die meine Vorträge der letzten Jahre über Alpine Linux, ifstate oder Linux Router interessant fanden bietet sich hier die Möglichkeit für praktische Erfahrungen und Austausch.
https://chemnitzer.linux-tage.de/2026/de/programm/beitrag/329
-
ifstate 2.2.4 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.2.4The 75th release includes various fixes & improvements like:
- make stable-privacy IPv6 addresses work
- resolve wireguard endpoints *after* configuring the network stack so that DNS resolution could workThis is the first release with published Debian packages: https://ifstate.net/2.2/docs/install/#debian-gnulinux
-
ifstate 2.2.4 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.2.4The 75th release includes various fixes & improvements like:
- make stable-privacy IPv6 addresses work
- resolve wireguard endpoints *after* configuring the network stack so that DNS resolution could workThis is the first release with published Debian packages: https://ifstate.net/2.2/docs/install/#debian-gnulinux
-
The ifstate git repository on #Codeberg has been moved from my personal account into the RouterKit project at https://codeberg.org/routerkit/ifstate
With moving the project it gains access to CI/CD runners and the first step is to use them to provide #Debian packages from the upcoming 2.2.4 release 🥳
https://codeberg.org/routerkit/-/packages/debian/ifstate/I already use it in prod for haproxy setups on Debian trixie using different network namespaces for listeners and server access.
-
The ifstate git repository on #Codeberg has been moved from my personal account into the RouterKit project at https://codeberg.org/routerkit/ifstate
With moving the project it gains access to CI/CD runners and the first step is to use them to provide #Debian packages from the upcoming 2.2.4 release 🥳
https://codeberg.org/routerkit/-/packages/debian/ifstate/I already use it in prod for haproxy setups on Debian trixie using different network namespaces for listeners and server access.
-
I don't like to maintain packaging upstream, but… I required netns configuration support on Debian for using network namespaces with haproxy!
Sadly I had to use dh_virtualenv because pyroute2 in Debian sid+stable is to old to have all required netns related features.
Haproxy has namespace support for listeners and servers which allows one to easily build multi-tenant load-balancing setups. 😎
-
I don't like to maintain packaging upstream, but… I required netns configuration support on Debian for using network namespaces with haproxy!
Sadly I had to use dh_virtualenv because pyroute2 in Debian sid+stable is to old to have all required netns related features.
Haproxy has namespace support for listeners and servers which allows one to easily build multi-tenant load-balancing setups. 😎
-
hank you, 2025 — what a year for RELIANOID.
From continuous product evolution and strong focus on security and performance, to supporting the Linux networking community and collaborating with partners worldwide — this year has been about growth, trust, and shared progress.
Huge thanks to our team, partners, and customers for being part of the journey.
Onwards to 2026 🚀#RELIANOID #ADC #LinuxNetworking #CyberSecurity #OpenSource #ThankYou
-
The ifstate 2.2 release - a tool for declarative network configuration for Linux - is available in the most recent stable releases of Alpine Linux 3.23 and NixOS 25.11. 🥳
Fun fact: this is the first NixOS release where you can use a declarative network configuration out of the box 😉
-
The ifstate 2.2 release - a tool for declarative network configuration for Linux - is available in the most recent stable releases of Alpine Linux 3.23 and NixOS 25.11. 🥳
Fun fact: this is the first NixOS release where you can use a declarative network configuration out of the box 😉
-
#ifstate 2.2.[01] - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.2.0
https://codeberg.org/liske/ifstate/releases/tag/2.2.1This release includes:
- support for vlan_flags (loose_binding, …)
- the wgnlpy python dependency has been dropped…and it also contains several fixes, the most import is a regression: interface defaults were not applied since ifstate 2.0
(already available in @alpinelinux edge + v3.23 and #nixpkgs unstable + 25.11)
-
#ifstate 2.2.[01] - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.2.0
https://codeberg.org/liske/ifstate/releases/tag/2.2.1This release includes:
- support for vlan_flags (loose_binding, …)
- the wgnlpy python dependency has been dropped…and it also contains several fixes, the most import is a regression: interface defaults were not applied since ifstate 2.0
(already available in @alpinelinux edge + v3.23 and #nixpkgs unstable + 25.11)
-
🐧💻 "Escape the Linux Networking Stack" – because understanding it makes it vanish! Poof! 💨 The author attempts to unravel the mystery, but spoiler alert: nobody truly escapes, not even Cloudflare's blog notifications. 🐟🔍
https://blog.cloudflare.com/so-long-and-thanks-for-all-the-fish-how-to-escape-the-linux-networking-stack/ #LinuxNetworking #EscapeTheStack #Cloudflare #TechMystery #NetworkingInsights #HackerNews #ngated -
🐧💻 "Escape the Linux Networking Stack" – because understanding it makes it vanish! Poof! 💨 The author attempts to unravel the mystery, but spoiler alert: nobody truly escapes, not even Cloudflare's blog notifications. 🐟🔍
https://blog.cloudflare.com/so-long-and-thanks-for-all-the-fish-how-to-escape-the-linux-networking-stack/ #LinuxNetworking #EscapeTheStack #Cloudflare #TechMystery #NetworkingInsights #HackerNews #ngated -
How to escape the Linux networking stack
#HackerNews #LinuxNetworking #EscapeTutorial #Cloudflare #TechInsights #NetworkingTips
-
How to escape the Linux networking stack
#HackerNews #LinuxNetworking #EscapeTutorial #Cloudflare #TechInsights #NetworkingTips
-
#ifstate 2.1.0 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.1.0This release includes:
- support for IP address IFA (local, proto, …)
- support for PtP link IP addressing
- wireguard: auto generation of peer routes from allowsips
- improved handling of LLA…and it also contains some bugfixes 😉
(already available in @alpinelinux edge, the #nixpkgs unstable PR is still pending https://github.com/NixOS/nixpkgs/pull/460206 )
-
#ifstate 2.1.0 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.1.0This release includes:
- support for IP address IFA (local, proto, …)
- support for PtP link IP addressing
- wireguard: auto generation of peer routes from allowsips
- improved handling of LLA…and it also contains some bugfixes 😉
(already available in @alpinelinux edge, the #nixpkgs unstable PR is still pending https://github.com/NixOS/nixpkgs/pull/460206 )
-
#TIL that there is a nice tool to determine the encapsulation overhead, the Visual packet size calculator by @dmbaturin
-
#TIL that there is a nice tool to determine the encapsulation overhead, the Visual packet size calculator by @dmbaturin
-
#ifstate 1.13.9 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/1.13.9This maintenance release for the old 1.x branch fixes an exception when reconfiguring tc filters when using pyroute2 0.9.1+
(already available in @alpinelinux 3.22 + 3.21 + 3.20 + 3.19)
2/2
-
#ifstate 1.13.9 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/1.13.9This maintenance release for the old 1.x branch fixes an exception when reconfiguring tc filters when using pyroute2 0.9.1+
(already available in @alpinelinux 3.22 + 3.21 + 3.20 + 3.19)
2/2
-
#ifstate 2.0.2 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.0.2This maintenance release contains mostly fixes for traffic control (TC) settings:
- fixes a regression breaking cshaper configurations
- fixes exceptions when reconfiguring tc filters when using pyroute2 0.9.1+1/2
-
#ifstate 2.0.2 - a tool for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.0.2This maintenance release contains mostly fixes for traffic control (TC) settings:
- fixes a regression breaking cshaper configurations
- fixes exceptions when reconfiguring tc filters when using pyroute2 0.9.1+1/2
-
#ifstate 2.0 - a tool to for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.0.0
https://codeberg.org/liske/ifstate/releases/tag/2.0.1The new major release contains various breaking changes and the config file schema has been refactored to better match the requirements. The new documentation contains a overview on the breaking changes when upgrading from ifstate 1.x: https://ifstate.net/2.0/docs/upgrades/#ifstate-20
This thread will highlight some of the most important changes!
1/4
-
#ifstate 2.0 - a tool to for declarative network configuration for Linux - was released:
https://codeberg.org/liske/ifstate/releases/tag/2.0.0
https://codeberg.org/liske/ifstate/releases/tag/2.0.1The new major release contains various breaking changes and the config file schema has been refactored to better match the requirements. The new documentation contains a overview on the breaking changes when upgrading from ifstate 1.x: https://ifstate.net/2.0/docs/upgrades/#ifstate-20
This thread will highlight some of the most important changes!
1/4
-
Essential nmcli Command Examples To Manage Network Connections On Linux #nmcli #NetworkManager #LinuxNetworking #Linuxadmin #linuxhowto #linuxbasics #linuxcommands #commandline
https://ostechnix.com/linux-nmcli-command-examples/