OpenConnect/ocserv container with dynamic iptables NAT rules.
This image is based on ghcr.io/chrissi2812/docker-openconnect-cisco:master and adds a small startup wrapper that reads the VPN IPv4 pool from ocserv.conf and refreshes the NAT rules on every container start.
The usual ocserv setup needs NAT/forwarding rules for the VPN client address pool. Hard-coding that range is fragile. If a user changes:
ipv4-network = 172.69.69.0
ipv4-netmask = 255.255.255.0
or uses:
ipv4-network = 10.77.0.0/24
the container automatically adapts the iptables rules at startup.
docker pull railline/openconnectserver:latest
docker run -d \
--name openconnectserver \
--privileged \
--restart unless-stopped \
-p 4443:4443/tcp \
-p 4443:4443/udp \
-e TZ=Europe/Paris \
-e LISTEN_PORT=4443 \
-e TUNNEL_MODE=all \
-e DNS_SERVERS=1.1.1.1,1.0.0.1 \
-v /path/to/openconnect/config:/config \
railline/openconnectserver:latest
Most behavior is inherited from the upstream image.
Common variables:
| Variable | Default | Description |
|---|---|---|
LISTEN_PORT | 4443 | ocserv TCP/UDP listen port handled by the upstream entrypoint. |
TUNNEL_MODE | all | all or split-include. |
TUNNEL_ROUTES | empty | Comma-separated routes for split-include. |
DNS_SERVERS | upstream default | Comma-separated DNS servers pushed to VPN clients. |
POWER_USER | no | If yes, the upstream entrypoint avoids rewriting parts of ocserv.conf. |
OCSERV_MANAGE_IPTABLES | yes | Set to no to disable this image's dynamic iptables setup. |
VPN_IPV4_NETWORK | from ocserv.conf | Optional override for the VPN pool, for example 10.77.0.0/24. |
VPN_IPV4_NETMASK | from ocserv.conf | Optional override when VPN_IPV4_NETWORK is not CIDR, for example 255.255.255.0. |
OCSERV_NAT_INTERFACE | auto-detect | Optional outbound interface, for example eth0. |
At each startup the image:
ipv4-network and ipv4-netmask from /config/ocserv.conf;MASQUERADE and FORWARD rules for the current VPN pool;net.ipv4.ip_forward when possible.The managed rules are tagged with comments beginning with railline-ocserv, so unrelated firewall rules are left alone.
Use privileged mode, map /config, and expose the chosen TCP/UDP port. The image is not Unraid-specific; the same image works with plain Docker and Compose.
services:
openconnectserver:
image: railline/openconnectserver:latest
container_name: openconnectserver
privileged: true
restart: unless-stopped
ports:
- "4443:4443/tcp"
- "4443:4443/udp"
environment:
TZ: Europe/Paris
LISTEN_PORT: "4443"
TUNNEL_MODE: all
DNS_SERVERS: 1.1.1.1,1.0.0.1
volumes:
- ./config:/config
This repository only adds a wrapper around the upstream image. Check the upstream image and ocserv licenses for the base components.
Content type
Image
Digest
sha256:993fd9935…
Size
18.8 MB
Last updated
5 months ago
docker pull railline/openconnectserver