OpenConnect: Difference between revisions
Appearance
No edit summary |
Fix vpn-slice usage for NixOS env |
||
| (One intermediate revision by the same user not shown) | |||
| Line 3: | Line 3: | ||
== Setup == | == Setup == | ||
Following example configures a permanent VPN connection using OpenConnect using the protocol <code>anyconnect</code>.<syntaxhighlight lang="nix"> | Following example configures a permanent VPN connection using OpenConnect using the protocol <code>anyconnect</code>.<syntaxhighlight lang="nix"> | ||
openconnect.interfaces.myvpn = { | networking.openconnect.interfaces.myvpn = { | ||
gateway = "vpn-ac.uni-heidelberg.de/2fa"; | gateway = "vpn-ac.uni-heidelberg.de/2fa"; | ||
protocol = "anyconnect"; | protocol = "anyconnect"; | ||
| Line 14: | Line 14: | ||
}; | }; | ||
</syntaxhighlight>Further you can also provide TOTP secrets for two-factor-authentications (which should be <u>avoided in production</u> environments since it decreases the security concept drastically) and use <code>vpn-slice</code> to achieve split tunneling instead of routing all traffic through the VPN gateway.<syntaxhighlight lang="nix"> | </syntaxhighlight>Further you can also provide TOTP secrets for two-factor-authentications (which should be <u>avoided in production</u> environments since it decreases the security concept drastically) and use <code>vpn-slice</code> to achieve split tunneling instead of routing all traffic through the VPN gateway.<syntaxhighlight lang="nix"> | ||
openconnect.interfaces.myvpn = { | networking.openconnect.interfaces.myvpn = { | ||
[...] | [...] | ||
extraOptions = { | extraOptions = { | ||
token-mode = "totp"; | token-mode = "totp"; | ||
token-secret = "base32:ABC123"; | token-secret = "base32:ABC123"; | ||
script = "${lib.getExe pkgs.vpn-slice} 129.206.0.0/16"; | script = "${lib.getExe pkgs.vpn-slice} --no-ns-hosts --no-host-names 129.206.0.0/16"; | ||
}; | }; | ||
}; | }; | ||
</syntaxhighlight> | </syntaxhighlight> | ||
We need to add <code>--no-ns-hosts --no-host-names</code> to <code>vpn-slice</code> since on NixOS <code>/etc/hosts</code> is read-only. | |||
[[Category:Networking]] | [[Category:Networking]] | ||
[[Category:VPN]] | [[Category:VPN]] | ||
Latest revision as of 22:35, 1 September 2026
OpenConnect is a free, open‑source client‑to‑site VPN that works with many commercial SSL‑VPN gateways, such as Cisco AnyConnect, Palo Alto GlobalProtect, Pulse Secure (including Pulse Connect Secure), Juniper Network Connect, Fortinet, F5 and Array Networks.
Setup
Following example configures a permanent VPN connection using OpenConnect using the protocol anyconnect.
networking.openconnect.interfaces.myvpn = {
gateway = "vpn-ac.uni-heidelberg.de/2fa";
protocol = "anyconnect";
user = "myuser";
passwordFile = "/etc/secrets/openconnect-secret";
extraOptions = {
useragent = "AnyConnect";
non-inter = true;
};
};
Further you can also provide TOTP secrets for two-factor-authentications (which should be avoided in production environments since it decreases the security concept drastically) and use vpn-slice to achieve split tunneling instead of routing all traffic through the VPN gateway.
networking.openconnect.interfaces.myvpn = {
[...]
extraOptions = {
token-mode = "totp";
token-secret = "base32:ABC123";
script = "${lib.getExe pkgs.vpn-slice} --no-ns-hosts --no-host-names 129.206.0.0/16";
};
};
We need to add --no-ns-hosts --no-host-names to vpn-slice since on NixOS /etc/hosts is read-only.