Sign inSign up

railline/openconnectserver

By railline

•Updated 5 months ago

Image
0

70

railline/openconnectserver repository overview

⁠railline/openconnectserver

OpenConnect/ocserv container with dynamic iptables NAT rules.

This image is based on ghcr.io/chrissi2812/docker-openconnect-cisco:master and adds a small startup wrapper that reads the VPN IPv4 pool from ocserv.conf and refreshes the NAT rules on every container start.

⁠Why

The usual ocserv setup needs NAT/forwarding rules for the VPN client address pool. Hard-coding that range is fragile. If a user changes:

ipv4-network = 172.69.69.0
ipv4-netmask = 255.255.255.0

or uses:

ipv4-network = 10.77.0.0/24

the container automatically adapts the iptables rules at startup.

⁠Image

docker pull railline/openconnectserver:latest

⁠Quick Start

docker run -d \
  --name openconnectserver \
  --privileged \
  --restart unless-stopped \
  -p 4443:4443/tcp \
  -p 4443:4443/udp \
  -e TZ=Europe/Paris \
  -e LISTEN_PORT=4443 \
  -e TUNNEL_MODE=all \
  -e DNS_SERVERS=1.1.1.1,1.0.0.1 \
  -v /path/to/openconnect/config:/config \
  railline/openconnectserver:latest

⁠Configuration

Most behavior is inherited from the upstream image.

Common variables:

VariableDefaultDescription
LISTEN_PORT4443ocserv TCP/UDP listen port handled by the upstream entrypoint.
TUNNEL_MODEallall or split-include.
TUNNEL_ROUTESemptyComma-separated routes for split-include.
DNS_SERVERSupstream defaultComma-separated DNS servers pushed to VPN clients.
POWER_USERnoIf yes, the upstream entrypoint avoids rewriting parts of ocserv.conf.
OCSERV_MANAGE_IPTABLESyesSet to no to disable this image's dynamic iptables setup.
VPN_IPV4_NETWORKfrom ocserv.confOptional override for the VPN pool, for example 10.77.0.0/24.
VPN_IPV4_NETMASKfrom ocserv.confOptional override when VPN_IPV4_NETWORK is not CIDR, for example 255.255.255.0.
OCSERV_NAT_INTERFACEauto-detectOptional outbound interface, for example eth0.

⁠Dynamic iptables

At each startup the image:

  1. reads ipv4-network and ipv4-netmask from /config/ocserv.conf;
  2. computes the VPN CIDR;
  3. removes old rules created by this image;
  4. adds fresh MASQUERADE and FORWARD rules for the current VPN pool;
  5. enables net.ipv4.ip_forward when possible.

The managed rules are tagged with comments beginning with railline-ocserv, so unrelated firewall rules are left alone.

⁠Unraid Notes

Use privileged mode, map /config, and expose the chosen TCP/UDP port. The image is not Unraid-specific; the same image works with plain Docker and Compose.

⁠Docker Compose

services:
  openconnectserver:
    image: railline/openconnectserver:latest
    container_name: openconnectserver
    privileged: true
    restart: unless-stopped
    ports:
      - "4443:4443/tcp"
      - "4443:4443/udp"
    environment:
      TZ: Europe/Paris
      LISTEN_PORT: "4443"
      TUNNEL_MODE: all
      DNS_SERVERS: 1.1.1.1,1.0.0.1
    volumes:
      - ./config:/config

⁠License

This repository only adds a wrapper around the upstream image. Check the upstream image and ocserv licenses for the base components.

Tag summary

Content type

Image

Digest

sha256:993fd9935…

Size

18.8 MB

Last updated

5 months ago

docker pull railline/openconnectserver