1 | .Dd 2002-03-25 |
1 | .\" Automatically generated by Pod::Man v1.36, Pod::Parser v1.13 |
2 | .Dt VPED 8 |
2 | .\" |
3 | .\" Manual page created by: |
3 | .\" Standard preamble: |
4 | .\" Ivo Timmermans <ivo@o2w.nl> |
4 | .\" ======================================================================== |
5 | .\" Guus Sliepen <guus@sliepen.eu.org> |
5 | .de Sh \" Subsection heading |
6 | .\" Modified extensively by Marc Lehmann <pcg@goof.com> |
6 | .br |
7 | .Sh NAME |
7 | .if t .Sp |
8 | .Nm vped |
8 | .ne 5 |
9 | .Nd Virtual Private Ethernet Daemon |
9 | .PP |
10 | .Sh SYNOPSIS |
10 | \fB\\$1\fR |
11 | .Nm |
11 | .PP |
12 | .Op Fl cdDkKnL |
12 | .. |
13 | .Op Fl -config Ns = Ns Ar DIR |
13 | .de Sp \" Vertical space (when we can't use .PP) |
14 | .Op Fl -no-detach |
14 | .if t .sp .5v |
15 | .Op Fl -debug Ns = Ns Ar [LEVEL] |
15 | .if n .sp |
16 | .Op Fl -kill Ns = Ns Ar [SIGNAL] |
16 | .. |
17 | .Op Fl -mlock |
17 | .de Vb \" Begin verbatim text |
18 | .Op Fl -help |
18 | .ft CW |
19 | .Op Fl -version |
19 | .nf |
20 | NODENAME |
20 | .ne \\$1 |
|
|
21 | .. |
|
|
22 | .de Ve \" End verbatim text |
|
|
23 | .ft R |
|
|
24 | .fi |
|
|
25 | .. |
|
|
26 | .\" Set up some character translations and predefined strings. \*(-- will |
|
|
27 | .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left |
|
|
28 | .\" double quote, and \*(R" will give a right double quote. | will give a |
|
|
29 | .\" real vertical bar. \*(C+ will give a nicer C++. Capital omega is used to |
|
|
30 | .\" do unbreakable dashes and therefore won't be available. \*(C` and \*(C' |
|
|
31 | .\" expand to `' in nroff, nothing in troff, for use with C<>. |
|
|
32 | .tr \(*W-|\(bv\*(Tr |
|
|
33 | .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' |
|
|
34 | .ie n \{\ |
|
|
35 | . ds -- \(*W- |
|
|
36 | . ds PI pi |
|
|
37 | . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch |
|
|
38 | . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch |
|
|
39 | . ds L" "" |
|
|
40 | . ds R" "" |
|
|
41 | . ds C` |
|
|
42 | . ds C' |
|
|
43 | 'br\} |
|
|
44 | .el\{\ |
|
|
45 | . ds -- \|\(em\| |
|
|
46 | . ds PI \(*p |
|
|
47 | . ds L" `` |
|
|
48 | . ds R" '' |
|
|
49 | 'br\} |
|
|
50 | .\" |
|
|
51 | .\" If the F register is turned on, we'll generate index entries on stderr for |
|
|
52 | .\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index |
|
|
53 | .\" entries marked with X<> in POD. Of course, you'll have to process the |
|
|
54 | .\" output yourself in some meaningful fashion. |
|
|
55 | .if \nF \{\ |
|
|
56 | . de IX |
|
|
57 | . tm Index:\\$1\t\\n%\t"\\$2" |
|
|
58 | .. |
|
|
59 | . nr % 0 |
|
|
60 | . rr F |
|
|
61 | .\} |
|
|
62 | .\" |
|
|
63 | .\" For nroff, turn off justification. Always turn off hyphenation; it makes |
|
|
64 | .\" way too many mistakes in technical documents. |
|
|
65 | .hy 0 |
|
|
66 | .if n .na |
|
|
67 | .\" |
|
|
68 | .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). |
|
|
69 | .\" Fear. Run. Save yourself. No user-serviceable parts. |
|
|
70 | . \" fudge factors for nroff and troff |
|
|
71 | .if n \{\ |
|
|
72 | . ds #H 0 |
|
|
73 | . ds #V .8m |
|
|
74 | . ds #F .3m |
|
|
75 | . ds #[ \f1 |
|
|
76 | . ds #] \fP |
|
|
77 | .\} |
|
|
78 | .if t \{\ |
|
|
79 | . ds #H ((1u-(\\\\n(.fu%2u))*.13m) |
|
|
80 | . ds #V .6m |
|
|
81 | . ds #F 0 |
|
|
82 | . ds #[ \& |
|
|
83 | . ds #] \& |
|
|
84 | .\} |
|
|
85 | . \" simple accents for nroff and troff |
|
|
86 | .if n \{\ |
|
|
87 | . ds ' \& |
|
|
88 | . ds ` \& |
|
|
89 | . ds ^ \& |
|
|
90 | . ds , \& |
|
|
91 | . ds ~ ~ |
|
|
92 | . ds / |
|
|
93 | .\} |
|
|
94 | .if t \{\ |
|
|
95 | . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" |
|
|
96 | . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' |
|
|
97 | . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' |
|
|
98 | . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' |
|
|
99 | . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' |
|
|
100 | . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' |
|
|
101 | .\} |
|
|
102 | . \" troff and (daisy-wheel) nroff accents |
|
|
103 | .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' |
|
|
104 | .ds 8 \h'\*(#H'\(*b\h'-\*(#H' |
|
|
105 | .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] |
|
|
106 | .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' |
|
|
107 | .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' |
|
|
108 | .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] |
|
|
109 | .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] |
|
|
110 | .ds ae a\h'-(\w'a'u*4/10)'e |
|
|
111 | .ds Ae A\h'-(\w'A'u*4/10)'E |
|
|
112 | . \" corrections for vroff |
|
|
113 | .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' |
|
|
114 | .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' |
|
|
115 | . \" for low resolution devices (crt and lpr) |
|
|
116 | .if \n(.H>23 .if \n(.V>19 \ |
|
|
117 | \{\ |
|
|
118 | . ds : e |
|
|
119 | . ds 8 ss |
|
|
120 | . ds o a |
|
|
121 | . ds d- d\h'-1'\(ga |
|
|
122 | . ds D- D\h'-1'\(hy |
|
|
123 | . ds th \o'bp' |
|
|
124 | . ds Th \o'LP' |
|
|
125 | . ds ae ae |
|
|
126 | . ds Ae AE |
|
|
127 | .\} |
|
|
128 | .rm #[ #] #H #V #F C |
|
|
129 | .\" ======================================================================== |
|
|
130 | .\" |
|
|
131 | .IX Title "VPED.8 8" |
|
|
132 | .TH VPED.8 8 "2003-03-28" "0.1" "Virtual Private Ethernet" |
|
|
133 | .SH "NAME" |
|
|
134 | \&\f(CW\*(C`vped\*(C'\fR \- Virtual Private Ethernet Daemon |
|
|
135 | =head1 SYNOPSIS |
|
|
136 | .PP |
|
|
137 | \&\f(CW\*(C`vped\*(C'\fR [\fB\-cDlL\fR] [\fB\-\-config=\fR\fIDIR\fR] [\fB\-\-no\-detach\fR] [\fB\-l=\fR\fILEVEL]\fR] |
|
|
138 | [\fB\-\-kill\fR[\fB=\fR\fISIGNAL\fR]] [\fB\-\-mlock\fR] [\fB\-\-help\fR] [\fB\-\-version\fR] |
|
|
139 | \&\fINODENAME\fR |
21 | .Sh DESCRIPTION |
140 | .SH "DESCRIPTION" |
|
|
141 | .IX Header "DESCRIPTION" |
22 | This is the manual page for vped, the virtual private ethernet daemon. |
142 | This is the manual page for vped, the virtual private ethernet daemon. |
23 | When started, |
143 | When started, \f(CW\*(C`vped\*(C'\fR will read it's configuration file to determine the |
24 | .Nm |
144 | network topology, and other configuration information, assuming the role |
25 | |
145 | of node \fI\s-1NODENAME\s0\fR. It will then connect to the tun/tap device and set |
26 | will read it's configuration file to determine the network topology, and |
146 | up a socket for incoming connections. Then a script will be executed to |
27 | other configuration information, assuming the role of node NODENAME. It |
147 | further configure the virtual device. If that succeeds, it will detach |
28 | will then connect to the tun/tap device and set up a socket for incoming |
148 | from the controlling terminal and continue in the background, accepting |
29 | connections. Then a script will be executed to further configure the |
|
|
30 | virtual device. If that succeeds, it will detach from the controlling |
|
|
31 | terminal and continue in the background, accepting and setting up |
|
|
32 | connections to other vped daemons that are part of the virtual private |
149 | and setting up connections to other vped daemons that are part of the |
33 | ethernet. |
150 | virtual private ethernet. |
34 | |
|
|
35 | .Sh OPTIONS |
151 | .SH "OPTIONS" |
36 | .Bl -tag -width indent |
152 | .IX Header "OPTIONS" |
37 | .It Fl c, -config Ns = Ns Ar DIR |
153 | .IP "\fB\-c\fR, \fB\-\-config=\fR\fI\s-1DIR\s0\fR" 4 |
|
|
154 | .IX Item "-c, --config=DIR" |
38 | Read configuration options from |
155 | Read configuration options from \fI\s-1DIR\s0\fR |
39 | .Ar DIR . |
156 | .IP "\fB\-d\fR, \fB\-\-l=\fR\fI\s-1LEVEL\s0\fR" 4 |
40 | .It Fl d, -debug Ns Op = Ns Ar LEVEL |
157 | .IX Item "-d, --l=LEVEL" |
41 | Increase debug level or set it to |
158 | Set logging level to \fI\s-1LEVEL\s0\fR (one of: noise, trace, debug, info, notice, |
42 | .Ar LEVEL |
159 | warn, error, critical). |
43 | (see below). |
160 | .IP "\fB\-\-help\fR" 4 |
44 | .It Fl -help |
161 | .IX Item "--help" |
45 | Display short list of options. |
162 | Display short list of options. |
46 | .It Fl k, -kill Ns Op = Ns Ar SIGNAL |
163 | .IP "\fB\-D\fR, \fB\-\-no\-detach\fR" 4 |
47 | Attempt to kill a running |
164 | .IX Item "-D, --no-detach" |
48 | .Nm |
165 | Don't fork and detach but stay in foreground and log messages to stderr in |
49 | (optionally with the specified |
166 | addition to syslog. |
50 | .Ar SIGNAL |
167 | .IP "\fB\-L\fR, \fB\-\-mlock\fR" 4 |
51 | instead of SIGTERM) and exit. |
168 | .IX Item "-L, --mlock" |
52 | .It Fl D, -no-detach |
169 | Lock \f(CW\*(C`vped\*(C'\fR into main memory. This will prevent sensitive data like |
53 | Don't fork and detach. |
|
|
54 | .It Fl L, -mlock |
|
|
55 | Lock vped into main memory. |
|
|
56 | This will prevent sensitive data like shared private keys to be written to the system swap files/partitions. |
170 | shared private keys to be written to the system swap files/partitions. |
57 | .It Fl -version |
171 | .IP "\fB\-\-version\fR" 4 |
|
|
172 | .IX Item "--version" |
58 | Output version information and exit. |
173 | Output version information and exit. |
59 | .El |
|
|
60 | .Sh SIGNALS |
174 | .SH "SIGNALS" |
61 | .Bl -tag -width indent |
175 | .IX Header "SIGNALS" |
62 | .It HUP |
176 | .IP "\s-1HUP\s0" 4 |
|
|
177 | .IX Item "HUP" |
63 | Closes all connections, resets the retry time and will start connecting again |
178 | Closes/resets all connections, resets the retry time and will start connecting |
64 | (it will NOT re-read the config file). This is useful e.g. in a /etc/ppp/if-up script. |
179 | again (it will \s-1NOT\s0 re-read the config file). This is useful e.g. in a |
65 | .El |
180 | \&\f(CW\*(C`/etc/ppp/if\-up\*(C'\fR script. |
66 | .Sh FILES |
181 | .IP "\s-1TERM\s0" 4 |
67 | .Bl -tag -width indent |
182 | .IX Item "TERM" |
|
|
183 | Closes/resets all connections and exits. |
|
|
184 | .IP "\s-1USR1\s0" 4 |
|
|
185 | .IX Item "USR1" |
|
|
186 | Dump current network status into the syslog (at loglevel \f(CW\*(C`notice\*(C'\fR, so make |
|
|
187 | sure your lgolevel allows this). |
|
|
188 | .SH "FILES" |
|
|
189 | .IX Header "FILES" |
|
|
190 | .ie n .IP "\*(C`/etc/vpe/vped.conf\*(C'" 4 |
|
|
191 | .el .IP "\f(CW\*(C`/etc/vpe/vped.conf\*(C'\fR" 4 |
68 | .It Pa /etc/vpe/vped.conf |
192 | .IX Item "/etc/vpe/vped.conf" |
69 | The configuration file for |
193 | The configuration file for \f(CW\*(C`vped\*(C'\fR. |
70 | .Nm . |
194 | .ie n .IP "\*(C`/etc/vpe/if\-up\*(C'" 4 |
71 | .It Pa /etc/vpe/if-up |
195 | .el .IP "\f(CW\*(C`/etc/vpe/if\-up\*(C'\fR" 4 |
|
|
196 | .IX Item "/etc/vpe/if-up" |
72 | Script which is executed as soon as the virtual network device has been allocated. |
197 | Script which is executed as soon as the virtual network device has been |
73 | Purpose is to further configure that device. |
198 | allocated. Purpose is to further configure that device. |
|
|
199 | .ie n .IP "\*(C`/etc/vpe/node\-up\*(C'" 4 |
|
|
200 | .el .IP "\f(CW\*(C`/etc/vpe/node\-up\*(C'\fR" 4 |
74 | .It Pa /etc/vpe/node-up |
201 | .IX Item "/etc/vpe/node-up" |
75 | Script which is executed whenever a node connects to this node. This can be used |
202 | Script which is executed whenever a node connects to this node. This can |
76 | for example to run nsupdate. |
203 | be used for example to run nsupdate. |
|
|
204 | .ie n .IP "\*(C`/etc/vpe/node\-down\*(C'" 4 |
|
|
205 | .el .IP "\f(CW\*(C`/etc/vpe/node\-down\*(C'\fR" 4 |
77 | .It Pa /etc/vpe/node-down |
206 | .IX Item "/etc/vpe/node-down" |
78 | Script which is executed whenever a conenction to another node is lost. |
207 | Script which is executed whenever a conenction to another node is lost. |
79 | for example to run nsupdate. |
208 | for example to run nsupdate. |
|
|
209 | .ie n .IP "\*(C`/etc/vpe/pubkey/*\*(C'" 4 |
|
|
210 | .el .IP "\f(CW\*(C`/etc/vpe/pubkey/*\*(C'\fR" 4 |
80 | .It Pa /etc/vpe/pubkey/* |
211 | .IX Item "/etc/vpe/pubkey/*" |
81 | The directory containing the public keys for every node, usually autogenerated |
212 | The directory containing the public keys for every node, usually |
82 | by executing vpectrl --generate-keys. |
213 | autogenerated by executing \f(CW\*(C`vpectrl \-\-generate\-keys\*(C'\fR. |
|
|
214 | .ie n .IP "\*(C`/var/run/vped.pid\*(C'" 4 |
|
|
215 | .el .IP "\f(CW\*(C`/var/run/vped.pid\*(C'\fR" 4 |
83 | .It Pa /var/run/vped.pid |
216 | .IX Item "/var/run/vped.pid" |
84 | The PID of the currently running |
217 | The \s-1PID\s0 of the currently running \f(CW\*(C`vped\*(C'\fR is stored in this file. |
85 | .Nm |
218 | .SH "BUGS" |
86 | is stored in this file. |
219 | .IX Header "BUGS" |
87 | .El |
220 | The cryptography in vped is not thoroughly checked by many people yet. Use |
88 | .Sh BUGS |
221 | it at your own risk! |
89 | .Sy The cryptography in vped is not well tested yet. Use it at your own risk! |
222 | .PP |
90 | .Pp |
|
|
91 | If you find any bugs, report them to vpe@plan9.de. |
223 | If you find any bugs, report them to \f(CW\*(C`vpe@plan9.de\*(C'\fR. |
92 | .Sh TODO |
224 | .SH "TODO" |
|
|
225 | .IX Header "TODO" |
93 | A lot. |
226 | A lot. |
94 | .Sh SEE ALSO |
227 | .SH "SEE ALSO" |
95 | .Xr vpe.conf 5 , |
228 | .IX Header "SEE ALSO" |
96 | .Xr vpectrl 8 , |
229 | \&\fIvpe\fR\|(5), \fIvped.conf\fR\|(5), \fIvpectrl\fR\|(8). |
97 | .Pp |
230 | .PP |
98 | The full documentation for vpe is maintained as a Texinfo manual. |
231 | vpe comes with \s-1ABSOLUTELY\s0 \s-1NO\s0 \s-1WARRANTY\s0. This is free software, and you are |
99 | If the info and tinc programs are properly installed at your site, |
232 | welcome to redistribute it under certain conditions; see the file \s-1COPYING\s0 |
100 | the command |
233 | for details. |
101 | .Ic info vpe |
|
|
102 | should give you access to the complete manual. |
|
|
103 | .Pp |
|
|
104 | vpe comes with ABSOLUTELY NO WARRANTY. |
|
|
105 | This is free software, and you are welcome to redistribute it under certain conditions; |
|
|
106 | see the file COPYING for details. |
|
|
107 | .Sh AUTHORS |
234 | .SH "AUTHORS" |
108 | .An "Marc Lehmann" Aq vpe@plan9.de |
235 | .IX Header "AUTHORS" |
109 | .Pp |
236 | Marc Lehmann \f(CW\*(C`<vpe@plan9.de>\*(C'\fR. |
|
|
237 | .PP |
110 | And thanks to many others for their contributions to vpe, especially the tincd authors |
238 | And thanks to many others for their contributions to vpe, especially the |
111 | who inspired this program and whose sourcecode I scavanged! |
239 | tincd authors, who inspired me to write this program (after scavenging |
|
|
240 | their sourcecode ;). |