NetworkManager 1.36ã«ããã¦L2TP/IPSecã®ãã³ãã«ãä¸æãå¼µããªãåé¡
NetworkManagerã®version 1.36ã«ããã¦L2TP/IPSecã®ãã³ãã«ãå¼µããã¨ããã¨ä¸æãå¼µããªãã¨ããåé¡ãããã¾ãã
èªåã使ç¨ãã¦ããUbuntu 22.04ã§ã¯L2TPæ¥ç¶ã¯æ¨æºã§ã¯æä¾ããã¦ããªãã®ã§network-manager-l2tpããã±ã¼ã¸ãaptçã§ã¤ã³ã¹ãã¼ã«ããå¿
è¦ãããã¾ããããã®æã«ä¸ç·ã«ä½¿ç¨ããNetworkManagerã®ãã¼ã¸ã§ã³ã«ãã£ã¦å½è©²åé¡ãçºçãã¾ããã¡ãªã¿ã«NetworkManagerã®ãã¼ã¸ã§ã³ã¯ nmcli --version
çã§åç
§å¯è½ã§ãã
Ubuntu 22.04ã®package managerã§å©ç¨å¯è½ãªNetworkManagerã®ãã¼ã¸ã§ã³ã¯1.36ç³»ã§ãããã *1 ã ããããã®åé¡ãè¸ããã¨ã«ãªãã¨æããã¾ãã
çç¶ã¨ãã¦ã¯ network-manager-l2tp
ãã¤ã³ã¹ãã¼ã«ããä¸ã§L2TP/IPSecæ¥ç¶ã試è¡ããã¨ä»¥ä¸ã®ãããªã¨ã©ã¼ã¡ãã»ã¼ã¸ã表示ãããä¸ã§ã©ãã¨ãéä¿¡ã§ããªããªããæçµçã«ãã³ãã«æ¥ç¶ã®ç¢ºç«ããã£ã³ã»ã«ãããã¨ãããã®ãè¦ããã¾ãã
NetworkManager[1134025]: xl2tpd[1134025]: handle_control: bad control packet! NetworkManager[1134025]: xl2tpd[1134025]: network_thread: bad packet
L2TPãIPSecã®è¨å®ã«åé¡ãããã®ãã¨æã£ã¦è²ã ã¨è©¦ãã¦ã¿ãã®ã§ããæ¹åãããè²ã 調ã¹ãã¨ããNetworkManagerã®éçºrepositoryã®issueã«è¡ãçãã¾ãã:
ããã¯æ¢ç¥ã®åé¡ã§ããããã§ã
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/946#note_1406609
ãã®ã³ã¡ã³ãã§ç¤ºããã¦ããããã«ããã³ãã«ã®ããã«ä½æãããpppã¤ã³ã¿ã¼ãã§ã¤ã¹ããããããããªãIPããæã£ã¦ãããã¨ã«ä¾ãããã§ãã
ä¾ç¤ºããã¦ããppp0ã®ç¶æ
ãåãã¦èª¬æããã¨ã
43: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1400 qdisc fq_codel state UNKNOWN group default qlen 3 link/ppp inet 172.16.100.10 peer 63.2.5.44/32 scope global ppp0 valid_lft forever preferred_lft forever inet 172.16.100.10/32 scope global noprefixroute ppp0 valid_lft forever preferred_lft forever
ãã³ãã«ã®å®å
63.2.5.44/32
ã«å¯¾ã㦠172.16.100.10
ãpeerããã¦ãããã¨ãåé¡ã®ããã§ãã
ã¨ããããã§ãã³ãã«ç¢ºç«è©¦è¡ä¸ã« ip a del 172.16.100.10 peer 63.2.5.44 dev ppp0
ãªã©ã¨ãã¦ãã®ä¸æ£ãªpeerãåé¤ãã¦ãããã¨ãæ£å¸¸ã«ãã³ãã«ãå¼µããã¦éä¿¡ã§ããããã«ãªãã¾ãã
ãã§ãããã§ãã......ã¨è¡ãããã¨ããã§ããããã®ã¾ã¾ã§ã¯ãã³ãã«ãå¼µããã³ã«æåã§peerã®åé¤ã³ãã³ããæããªããã°ãªããªãã®ã§ããã¯é¢åã§ãããããããã®åé¤ã³ãã³ãã¯ãã³ãã«ç¢ºç«å¦çä¸ã«æããªããã°ãªãããé©åãªã¿ã¤ãã³ã°ã§ã®å®è¡ãæ±ãããã¦å¤§å±¤é¢åã§ããèªååãã¾ãããã
NetworkManagerã«ã¯çºçããã¤ãã³ãã«å¿ãã¦ã¹ã¯ãªãããå¼ã°ããã¨ããä»çµã¿ãããã®ã§ãããå©ç¨ãã¾ãã
/etc/network/if-up.d
ã«å®è¡å¯è½ãªã¹ã¯ãªãããç½®ãã¦ããã¨ã¤ã³ã¿ã¼ãã§ã¤ã¹ãupããæã«å¼ã°ããã®ã§ã
#!/bin/bash set -euo pipefail if [[ "$IFACE" =~ ^ppp[0-9]+ ]]; then invalid_addr_json=$(ip -j addr show dev "$IFACE" | jq -r '.[0].addr_info[] | select(.scope == "global" and .address != null)') sudo ip a del "$(echo "$invalid_addr_json" | jq -r .local)" \ peer "$(echo "$invalid_addr_json" | jq -r .address)/$(echo "$invalid_addr_json" | jq -r .prefixlen)" \ dev "$IFACE" fi
ã¨ãããããªã¹ã¯ãªããã 999-remove-invalid-peer-on-ppp-if
ã¿ãããªåå㧠/etc/network/if-up.d
é
ä¸ã«ç½®ãã¦ããã¨ãL2TPãã³ãã«ç¢ºç«ã®éã«èªåçã«ä¸æ£ãªpeerãé¤å»ãããã®ã§æ£å¸¸ã«ãã³ãã«ãå¼µããããã«ãªãã¾ããjqã¯ã¤ã³ã¹ãã¼ã«ãã¦ããã¾ãããã
ãã ããä»ã®ç¨éã§pppã¤ã³ã¿ã¼ãã§ã¤ã¹ãå©ç¨ããéã«ãã®ã¹ã¯ãªãããæå¹ã«ãªã£ã¦ããã¨ãæå³ããåä½ããããããã¦ãã¾ãå¯è½æ§ãããã®ã§ãã®ç¹ã«ã¤ãã¦ã¯ãçæãã ããã
ãªããã®æããã®ã¹ã¯ãªããã«å®è¡å¯è½ãªpermissionãä¸ãã¦ããªãã¨ä¸æãåããªãã®ã§æ³¨æãå¿
è¦ã§ããchmod 755
ãªã©ã¨ãã¦ä¸ãã¾ãããã
ãã§ãããã§ãããããã¯ããã¨ã㦠ip
ã³ãã³ãã®çµæãJSONã§åºåãã -j
ãªãã·ã§ã³ã¯ä¾¿å©ã§ããã§ããã
ã¡ãªã¿ã«
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/946#note_1725575
ãã®ã³ã¡ã³ãã«ããããã«ãNetworkManager 1.40ã§ã¯ç´ã£ã¦ããåé¡ã®ããã§ããã¢ããã°ã¬ã¼ãã§ãããªãã¢ããã°ã¬ã¼ãããã»ããè¯ãã§ããããUbuntu 22.04ã®package managerã«ãå ¥ã£ã¦ã»ããã§ãããã¡ãã£ã¨é£ããããªã®ã§Ubuntu 24.04ãå¾ ã¤ãããªããããªäºæããã¦ãã¾ããUbuntu 23.04ã§ã¯NwtworkManager 1.42ãå©ç¨ãã¦ããã®ã§ *2 24.04ã§ã¯ä¿®æ£çã使ããããã«ãªããã¨ãæå¾ ãã¦ãã¾ãã