LINUXOR.SK ... open source notes ...

Namespaces 07 - Connecting two network namespaces (ns1, ns2) - with a veth pair

category: learnz/namespaces · date: 2016-11-01 · updated: 2017-01-16 · theme: github

Linux Namespaces Learning · Previous: Connecting a network namespace to the host system - with a veth pair · Next: Connecting two network namespaces (ns1, ns2) - with two veth pairs and a standard Linux bridge

The Slovak original of this document: Namespaces 07 - Prepojenie dvoch sieťových menných priestorov (ns1, ns2) - pomocou páru veth adaptérov (slovensky).

2016 - Linux NET Namespace - Connecting two network namespaces (ns1, ns2) - with a veth pair

1 Diagram

asciiart
                        +--------------------+                       +--------------------+
    (PID = 12112)       | ns1          veth1 |=========cable=========| veth2          ns2 |     (PID = 12130)
                        +--------------------+                       +--------------------+
                           namespace "ns1"                               namespace "ns2"

2 Creating network namespaces

Create two network (NET) namespaces, "ns1" and "ns2".

asciiart
# ip netns add ns1
# ip netns add ns2

3 Running processes inside namespaces

asciiart
[1]TERM1# ip netns exec ns1 bash
[2]TERM1# echo $$
----------------------------------------------------------------------------------------------------------------
12112
----------------------------------------------------------------------------------------------------------------
[3]TERM2# ip netns exec ns2 bash
[4]TERM2# echo $$
----------------------------------------------------------------------------------------------------------------
12130

4 Creating a pair of virtual Ethernet devices

plugs, then put one end (veth1) into namespace "ns1" and the other end (veth2) into namespace "ns2".

asciiart
[1]# ip link add veth1 type veth peer name veth2
[2]# ip link set veth1 netns ns1
[3]# ip link set veth2 netns ns2

5 Bringing the virtual Ethernet devices up in the namespaces and testing communication

asciiart
[1] # ip netns exec ns1 ifconfig veth1 10.0.0.1/24 up
[2]# ip netns exec ns2 ifconfig veth2 10.0.0.2/24 up
[3]# ip netns exec ns1 ping 10.0.0.2
----------------------------------------------------------------------------------------------------------------
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.022 ms
64 bytes from 10.0.0.2: icmp_seq=2 ttl=64 time=0.036 ms
...
----------------------------------------------------------------------------------------------------------------
[4]# ip netns exec ns2 ping 10.0.0.1
----------------------------------------------------------------------------------------------------------------
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.026 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.069 ms
...

Current practice (checked 2026-10)

noteThe article above is kept as it was written in 2016. This section lists what has changed since and what to do instead today.

The lab as an ordinary user (the prompt changes to # inside the user namespace):

bash
$ unshare --user --map-root-user --net --mount bash
$ # mount -t tmpfs tmpfs /run
$ # ip netns add ns1
$ # ip netns add ns2
$ # ip link add veth1 netns ns1 type veth peer name veth2 netns ns2
$ # ip -n ns1 addr add 10.0.0.1/24 dev veth1
$ # ip -n ns1 link set veth1 up
$ # ip -n ns2 addr add 10.0.0.2/24 dev veth2
$ # ip -n ns2 link set veth2 up
$ # ip netns exec ns1 ping -c1 10.0.0.2

Sources:

← learnz/namespaces(EN | SK)