Namespaces 09 - Connecting two network namespaces (ns1, ns2) - with two veth pairs and a distributed OVS switch (openvswitch)
Linux Namespaces Learning · Previous: Connecting two network namespaces (ns1, ns2) - with two veth pairs and a standard Linux bridge · Next: Connecting two network namespaces (ns1, ns2) - with two ports on a distributed OVS switch (openvswitch)
The Slovak original of this document: Namespaces 09 - Prepojenie dvoch sieťových menných priestorov (ns1, ns2) - pomocou 2 párov veth adaptérov a distribuovaného prepínača OVS (openvswitch) (slovensky).
2016 - Linux NET Namespace - Connecting two network namespaces (ns1, ns2) - with two veth pairs and a distributed OVS switch (openvswitch)
======================================================================================================================
[1] NET namespace - Connecting two network namespaces (ns1, ns2) - with two veth pairs and
a distributed OVS switch (openvswitch)
======================================================================================================================
+------------------+ +-------------------------------+ +------------------+
| ns1 veth1 |======cable======| veth1-ovs ovs0 veth2-ovs |======cable======| veth2 ns2 |
+------------------+ +-------------------------------+ +------------------+
namespace "ns1" host system (openvswitch) namespace "ns2"
The first Ethernet cable (between namespace "ns1" and the OVS switch "ovs0"): veth1====veth1-ovs
The second Ethernet cable (between namespace "ns2" and the OVS switch "ovs0"): veth2====veth2-ovs
These test scenarios use RedHat Linux 7.3, which does carry the kernel module for Openvswitch, but
no longer carries the user tools that administer openvswitch (ovs-vsctl). Those user tools are
carried in other Redhat products such as Red Hat Openstack Platform and the like. At this point
there is nothing for it but to install Openvswitch from source, see [1.0.X].
[1.0.1] Installing the distributed switch Openvswitch successfully needs the tools to compile it and
the libraries that Openvswitch uses.
----------------------------------------------------------------------------------------------------------------
# yum install gcc make python-devel openssl-devel kernel-devel graphviz kernel-debug-devel autoconf automake \
rpm-build redhat-rpm-config libtool checkpolicy selinux-policy-devel python-six
----------------------------------------------------------------------------------------------------------------
[1.0.2] - Create a directory to build the RPM package from source in, and download the current source package
for Openvswitch.
----------------------------------------------------------------------------------------------------------------
# mkdir -p /root/rpmbuild/SOURCES
# cd /root/rpmbuild/SOURCES
# wget http://openvswitch.org/releases/openvswitch-2.6.1.tar.gz
----------------------------------------------------------------------------------------------------------------
[1.0.3] - Unpack the source package, compile it and build the RPM package
The RPM packages for Openvswitch appear in "/root/rpmbuild/RPMS/x86_64/"
----------------------------------------------------------------------------------------------------------------
# cd /root/rpmbuild/SOURCES/
# tar -xvf ./openvswitch-2.6.1.tar.gz
# sed 's/openvswitch-kmod, //g' openvswitch-2.6.1/rhel/openvswitch.spec > openvswitch-2.6.1/rhel/openvswitch_no_kmod.spec
# rpmbuild -bb --nocheck openvswitch-2.6.1/rhel/openvswitch_no_kmod.spec
----------------------------------------------------------------------------------------------------------------
[1.0.4] - Install the RPM package with Openvswitch
----------------------------------------------------------------------------------------------------------------
# cd /root/rpmbuild/RPMS/x86_64/
# yum localinstall ./openvswitch-2.6.1-1.x86_64.rpm
----------------------------------------------------------------------------------------------------------------
[1.1] - Remove the network namespaces "ns1" and "ns2" (if they exist).
[1.2] - Create two network (NET) namespaces, "ns1" and "ns2".
----------------------------------------------------------------------------------------------------------------
[1.1]# ip netns del ns1 &>/dev/null
[1.1]# ip netns del ns2 &>/dev/null
[1.2]# ip netns add ns1
[1.2]# ip netns add ns2
----------------------------------------------------------------------------------------------------------------
[1.3] - On the host system, start Openvswitch and
[1.3] - create a distributed (openvswitch) Ethernet switch/bridge named "ovs0".
----------------------------------------------------------------------------------------------------------------
[1.3]# /etc/init.d/openvswitch start
[1.3]# ovs-vsctl add-br ovs0
----------------------------------------------------------------------------------------------------------------
[1.4]TERM1 - In network namespace "ns1", exec the command "bash".
[1.5]TERM2 - In network namespace "ns2", exec the command "bash".
----------------------------------------------------------------------------------------------------------------
[1.4]TERM1# ip netns exec ns1 bash
[1.5]TERM2# ip netns exec ns2 bash
----------------------------------------------------------------------------------------------------------------
[1.6] - Create a pair of virtual Ethernet devices, which stand for a network cable with two RJ45
plugs, then put one end (veth1) into namespace "ns1" and the other end
(veth1-ovs) into the distributed Ethernet switch "ovs0".
[1.7] - Put the virtual Ethernet adapter "veth1" into network namespace "ns1".
[1.8] - Connect the virtual Ethernet adapter "veth1-ovs" to the distributed Ethernet switch "ovs0".
[1.9] - Create a pair of virtual Ethernet devices, which stand for a network cable with two RJ45
plugs, then put one end (veth2) into namespace "ns2" and the other end
(veth2-ovs) into the distributed Ethernet switch "ovs0".
[1.10] - Put the virtual Ethernet adapter "veth2" into network namespace "ns2".
[1.11] - Connect the virtual Ethernet adapter "veth2-ovs" to the distributed Ethernet switch "ovs0".
----------------------------------------------------------------------------------------------------------------
[1.6] # ip link add veth1 type veth peer name veth1-ovs
[1.7] # ip link set veth1 netns ns1
[1.8] # ovs-vsctl add-port ovs0 veth1-ovs
[1.9] # ip link add veth2 type veth peer name veth2-ovs
[1.10]# ip link set veth2 netns ns2
[1.11]# ovs-vsctl add-port ovs0 veth2-ovs
----------------------------------------------------------------------------------------------------------------
[1.12] - Bring the network adapter "veth1" up in namespace "ns1" and give it the address "10.0.0.1".
[1.13] - Bring the network adapter/port "veth1-ovs" up on the distributed switch "ovs0".
[1.14] - Bring the network adapter "veth2" up in namespace "ns2" and give it the address "10.0.0.2".
[1.15] - Bring the network adapter/port "veth2-ovs" up on the distributed switch "ovs0".
[1.16] - From network namespace "ns1", test that namespace "ns2" answers.
[1.17] - From network namespace "ns2", test that namespace "ns1" answers.
----------------------------------------------------------------------------------------------------------------
[1.12]# ip netns exec ns1 ifconfig veth1 10.0.0.1/24 up
[1.13]# ip link set dev veth1-ovs up
[1.14]# ip netns exec ns2 ifconfig veth2 10.0.0.2/24 up
[1.15]# ip link set dev veth2-ovs up
[1.16]# ip netns exec ns1 ping 10.0.0.2
[1.17]# ip netns exec ns2 ping 10.0.0.1
----------------------------------------------------------------------------------------------------------------Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2016. This section lists what has changed since and what to do instead today.
- Platform: the lab uses RHEL 7.3 and Open vSwitch 2.6.1, both from 2016. RHEL 7 is out of maintenance support and 2.6.1 is many releases behind; do not rebuild this setup as written.
- Installing Open vSwitch: steps [1.0.1] to [1.0.4] build an RPM from a tarball as root in
/root/rpmbuild. Today take the distribution package where there is one (openvswitchon Fedora and openSUSE,openvswitch-switchon Debian and Ubuntu); it is signed and updated by the distribution. - If it has to be built: the tarball in step [1.0.2] is fetched over plain
http://and never verified. Upstream serves releases athttps://www.openvswitch.org/releases/. The documented build isdnf builddepon the spec file followed bymake rpm-fedora, which replaces the hand-made package list and thesededit of the spec. Build as an ordinary user, not as root. - Starting the service:
/etc/init.d/openvswitch startis replaced by the systemd unit shipped in the RPM:systemctl start openvswitch. ifconfig: steps [1.12] and [1.14] becomeip -n ns1 addr add 10.0.0.1/24 dev veth1andip -n ns1 link set veth1 up(the same forns2). Steps [1.4] and [1.5], thebashin each namespace, are not needed.- Repeatable setup:
ovs-vsctl --may-exist add-br ovs0does nothing if the bridge already exists, which fits the "remove if they exist" style of step [1.1]. - Root stays: unlike the veth and Linux bridge labs of this series, this one cannot be moved into an unprivileged user namespace as it stands: Open vSwitch runs as system daemons (
ovsdb-server,ovs-vswitchd) started by root. If plain layer 2 switching between two namespaces is all that is needed, the bridge from the previous article does it with iproute2 only.
The service and the bridge today:
$ # systemctl start openvswitch $ # ovs-vsctl --may-exist add-br ovs0
Sources: