Sign inSign up

weikinhuang/openconnect-web

By weikinhuang

•Updated about 1 year ago

Image
1

10K+

weikinhuang/openconnect-web repository overview

⁠OpenConnect Container Web Interface

This is a OpenConnect (Cisco VPN) client docker container that includes a web interface to be able to login.

It can be used to route other containers or the docker host through the connected vpn.

⁠What is OpenConnect

OpenConnect⁠ is an SSL VPN client initially created to support Cisco's AnyConnect SSL VPN. It has since been ported to support the Juniper SSL VPN (which is now known as Pulse Connect Secure), and to the Palo Alto Networks GlobalProtect SSL VPN. It uses the TUN/TAP driver in Linux kernel 2.4 and above and device tun(4) on BSD. The created connection is presented as a tunneling network device to the local system.

⁠How to use this image

This openconnect container was designed to be started first to provide a connection to other containers (using --net=container:openconnect or --net=host, see below Starting an openconnect client instance).

NOTE: Special privileges are required to run this container --cap-add=NET_ADMIN to be able to create the required interfaces and set up the proper firewall rules.

NOTE: If running with --cap-drop=all additional privileges are required on top of --cap-add=NET_ADMIN.

NOTE: If running with --net=host a system group must be added with the name vpn and gid 64501.

--cap-add=MKNOD
--cap-add=NET_ADMIN
--cap-add=NET_RAW
--cap-add=SETGID

NOTE: Traffic forwarding must be set up on the linux host

sysctl -w net.ipv4.conf.default.forwarding=1
sysctl -w net.ipv4.conf.all.forwarding=1
⁠Starting an openconnect client instance
docker run -it --name openconnect --cap-add=NET_ADMIN \
    -p 8000:8000 \
    weikinhuang/openconnect-web \
      -r "$[MACHINE_IP]/32" \
      -r "[DOCKER_BRIDGE_SUBNET]/16"

Once it's up other containers can be started using it's network connection:

docker run -it --net=container:openconnect -d some/docker-container
⁠Access the web client to connect/disconnect the vpn

Visit the site

http://[docker-machine-ip]:8000
⁠Routing for local access to non HTTP proxy-able ports

The argument -r must be your local network that you would connect to the server running the docker containers on. Running the following on your docker host should give you the correct network: ip route | awk '!/ (docker0|br-)/ && /src/ {print $1}'

⁠Configuration

⁠openconnect-web Arguments
-f                        # [optional] If enabled, no outbound traffic is allowed when the vpn is disconnected
-d                        # [optional] Disables updating the resolv.conf file on vpn connection
-p <port>                 # [optional] [multiple] Allow inbound port forwarding on specified port
-R <network>              # [optional] [multiple] IPv6 routes to send through the default gateway and allow
                          #     through the firewall
                          #     ex. ::1/64
-r <network>              # [optional] [multiple] IPv4 routes to send through the default gateway and allow
                          #     through the firewall
                          #     ex. 192.168.8.0/24
-L <network>              # [optional] [multiple] IPv6 routes to skip postrouting nat tun device and allow
                          #     through the firewall
                          #     ex. ::1/64
-l <network>              # [optional] [multiple] IPv4 routes to skip postrouting nat tun device and allow
                          #     through the firewall
                          #     ex. 192.168.8.0/24
-S <network>              # [optional] [multiple] IPv6 routes to send through the vpn connection
                          #     Setting this option automatically sets up split tunneling
                          #     ex. 10.0.0.0/8
-s <network>              # [optional] [multiple] IPv4 routes to send through the vpn connection
                          #     Setting this option automatically sets up split tunneling
                          #     ex. 0:0:0:0:0:ffff:a00:0/64
-a <hostname>             # [optional] [multiple] A hostname or url to query for IPv4 addresses to send through
                          #     the default route
                          #     ex. https://google.com or google.com
⁠Environment Variables
OCVPN_GATEWAY_OPTIONS     # [optional] A comma separated list of gateway hostnames to show in the web ui
                          #     ex. foo.corp.example.com,bar.corp.example.com
OCVPN_GATEWAY_DEFAULT     # [optional] The default gateway to show in the web ui, defaults to the
                          #            first option of OCVPN_GATEWAY_OPTIONS

OCVPN_GATEWAY             # [optional] Server defined ssl gateway, hides the option in the web ui
OCVPN_SERVER_SIGNATURE    # [optional] SHA signature of the ssl cert of the server

OCVPN_NO_PULL_DNS         # [optional] Disables updating the resolv.conf file on vpn connection

OCVPN_OPTIONS             # [optional] A list of openconnect options in config file format separated by semicolons
                          #     ex. authgroup GROUP;token-secret SECRET;disable-ipv6
OCVPN_PROTOCOL            # [optional] openconnect protocol to use
                          #     one of: anyconnect, nc, gp, pulse
                          #     defaults to anyconnect

PASSWORD_PARTIALS         # [optional] A comma separated list of fields to create the password from,
                          #            the order of the list is the concat order sent as the password
                          #     ex. foo,totp

DISABLE_IPTABLES_V6       # [optional] If set, disables usage of ip6tables

TUN_INTERFACE             # [optional] Name of the tun device. defaults to tun0
MANAGE_POSTROUTING_NAT    # [optional] If set, when the vpn connects & disconnects, postrouting rules will be swapped
                          #            to the active default route's interface

BIND_ADDRESS              # [optional] Address to bind the Web UI to. defaults to 0.0.0.0
                          #            Multiple addresses can be specified separated by ";"
                          #     ex. 127.0.0.1;192.168.1.100
PORT                      # [optional] Port to serve the web ui. defaults to 8000
INSECURE_PORT             # [optional] If https is enabled, also run a non https server on the specified port.
                          #            If this is not specified and https is enabled, the plaintext server is disabled.
                          #            This option is not used if https is disabled.

HTTPS_ENABLED             # [optional] Enable self-signed certificate generation and https for web server
HTTPS_CERT_FILE           # [optional] Path to the ssl cert file, enables https for web server, requires HTTPS_KEY_FILE
HTTPS_KEY_FILE            # [optional] Path to the ssl key file, enables https for web server, requires HTTPS_CERT_FILE

PAC_FILE                  # [optional] The PAC content to serve /api/proxy/proxy.pac for auto socks5 proxy configuration
PAC_FILE_PATH             # [optional] The PAC file to serve /api/proxy/proxy.pac for auto socks5 proxy configuration
PAC_SOCKS_PORT            # [optional] Default port the socks5 proxy serve is located. defaults to 1080, can be override
                          #            from the url /api/proxy/proxy.pac?port=PORT

GP_VPN_PORTAL_URL         # [optional] GlobalProtect only
                          #            The gateway portal url of the vpn, not the direct vpn egress.
                          #     ex. https://vpn.example.com
GP_VPN_TWO_STEP_REAUTH    # [optional] GlobalProtect only
                          #            If set to 1, it will try to reauthenticate to the gateway vpn in addition to the
                          #            portal url.
GP_VPN_LOGIN_AUTH         # [optional] GlobalProtect only
                          #            If set to 1, it will try get the actual login cookie from the gateway, and not #            use the prelogin cookie.

OKTA_URL                  # [optional] GlobalProtect only
                          #            Validated Okta 2fa url, if not provided, it will use the url from the vpn portal.
                          #     ex. https://okta.example.com
OKTA_MFA_TYPES            # [optional] GlobalProtect only
                          #            A comma separated list of supported 2fa methods, in the order to be tried.
                          #     any of: token:software:totp, sms, push, token
                          #     defaults to all, in the above order
⁠Config Files

A server-signatures.json can be provided as a json object list of pre-approved server signatures, the following locations are searched in order, and will use the first valid file.

  • /run/secret/server-signatures/server-signatures.json
  • /var/run/secret/server-signatures/server-signatures.json
  • /run/secret/server-signatures.json
  • /var/run/secret/server-signatures.json
  • /server-signatures.json

The file format is:

{
  "vpn.foo.com": "pin-sha256:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
}
⁠Hooks

Additional hook scripts can be specified to run on specific events. Hooks can be mounted to /hooks.d.

EventFilename
connect/hooks.d/*-connect.shAfter the vpn has successfully connected
disconnect/hooks.d/*-disconnect.shAfter the vpn has successfully disconnect
pre-script/hooks.d/*-pre-script.shBefore running the vpnc-script command
post-script/hooks.d/*-post-script.shAfter running the vpnc-script command if it is successful

Tag summary

Content type

Image

Digest

sha256:7aae8d46d…

Size

106.1 MB

Last updated

about 1 year ago

docker pull weikinhuang/openconnect-web