9 ms·
> And netns is for single-host isolation. This is a router forwarding LAN→WAN. Different problem Not at all. Put the LAN interface in a network namespace tha
by dontdoxxme 10mo ago
> And netns is for single-host isolation. This is a router forwarding LAN→WAN. Different problem
Not at all. Put the LAN interface in a network namespace that is different to the host (ip link set ... netns ...).
This gives you your "kill switch" without even needing firewall rules, it happens on a lower level.
- yoloshii 10mo agoIn this setup the "kill switch" works in tandem with the VPN server failover logic. Maybe a netns would be good for redundancy.