Namespaces 07 - Connecting two network namespaces (ns1, ns2) - with a veth pair
Linux Namespaces Learning · Previous: Connecting a network namespace to the host system - with a veth pair · Next: Connecting two network namespaces (ns1, ns2) - with two veth pairs and a standard Linux bridge
The Slovak original of this document: Namespaces 07 - Prepojenie dvoch sieťových menných priestorov (ns1, ns2) - pomocou páru veth adaptérov (slovensky).
2016 - Linux NET Namespace - Connecting two network namespaces (ns1, ns2) - with a veth pair
1 Diagram
+--------------------+ +--------------------+
(PID = 12112) | ns1 veth1 |=========cable=========| veth2 ns2 | (PID = 12130)
+--------------------+ +--------------------+
namespace "ns1" namespace "ns2"2 Creating network namespaces
Create two network (NET) namespaces, "ns1" and "ns2".
# ip netns add ns1 # ip netns add ns2
3 Running processes inside namespaces
- [1]TERM1 - In network namespace "ns1", exec the command "bash". PID = 12112
- [2]TERM1 - Find the PID of the BASH process.
- [3]TERM2 - In network namespace "ns2", exec the command "bash". PID = 12130
- [4]TERM2 - Find the PID of the BASH process.
[1]TERM1# ip netns exec ns1 bash [2]TERM1# echo $$ ---------------------------------------------------------------------------------------------------------------- 12112 ---------------------------------------------------------------------------------------------------------------- [3]TERM2# ip netns exec ns2 bash [4]TERM2# echo $$ ---------------------------------------------------------------------------------------------------------------- 12130
4 Creating a pair of virtual Ethernet devices
- [1] - Create a pair of virtual Ethernet devices, which stand for a network cable with two RJ45
plugs, then put one end (veth1) into namespace "ns1" and the other end (veth2) into namespace "ns2".
- [2] - Put the virtual Ethernet adapter "veth1" into network namespace "ns1".
- [3] - Put the virtual Ethernet adapter "veth2" into network namespace "ns2".
[1]# ip link add veth1 type veth peer name veth2 [2]# ip link set veth1 netns ns1 [3]# ip link set veth2 netns ns2
5 Bringing the virtual Ethernet devices up in the namespaces and testing communication
- [1] - Bring the network adapter "veth1" up in namespace "ns1" and give it the address "10.0.0.1".
- [2] - Bring the network adapter "veth2" up in namespace "ns2" and give it the address "10.0.0.2".
- [3] - From network namespace "ns1", test network communication with network namespace "ns2".
- [4] - From network namespace "ns2", test network communication with network namespace "ns1".
[1] # ip netns exec ns1 ifconfig veth1 10.0.0.1/24 up [2]# ip netns exec ns2 ifconfig veth2 10.0.0.2/24 up [3]# ip netns exec ns1 ping 10.0.0.2 ---------------------------------------------------------------------------------------------------------------- 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.022 ms 64 bytes from 10.0.0.2: icmp_seq=2 ttl=64 time=0.036 ms ... ---------------------------------------------------------------------------------------------------------------- [4]# ip netns exec ns2 ping 10.0.0.1 ---------------------------------------------------------------------------------------------------------------- 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.026 ms 64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.069 ms ...
Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2016. This section lists what has changed since and what to do instead today.
- The whole lab without root: nothing here has to touch the host. Start a shell in a new user, network and mount namespace and mount a tmpfs on
/runinside it;ip netns addthen works for an ordinary user, because the "root" of the user namespace owns everything created in it. On exit all of it is gone. - One command places both ends: sections 4 [1] to [3] create the pair on the host and move each end.
ip link addcan create the ends directly in their namespaces. - No shells needed in the namespaces: section 3 starts
bashinns1andns2only to read the PIDs, which the later steps do not use. Named namespaces persist without any process. ifconfig: replaced byip -n NAME addr addandip -n NAME link set ... up; net-tools is obsolete by its own man page.- Cleanup:
ip netns del ns1is enough. A veth device is destroyed with its namespace, and its peer goes with it.
The lab as an ordinary user (the prompt changes to # inside the user namespace):
$ unshare --user --map-root-user --net --mount bash $ # mount -t tmpfs tmpfs /run $ # ip netns add ns1 $ # ip netns add ns2 $ # ip link add veth1 netns ns1 type veth peer name veth2 netns ns2 $ # ip -n ns1 addr add 10.0.0.1/24 dev veth1 $ # ip -n ns1 link set veth1 up $ # ip -n ns2 addr add 10.0.0.2/24 dev veth2 $ # ip -n ns2 link set veth2 up $ # ip netns exec ns1 ping -c1 10.0.0.2
Sources: