vzctl set 55716 --devices c:10:200:rw --save vzctl set 55716 --capability net_admin:on --save
And create the character device file inside the container (execute the following on the host node): vzctl exec 55716 mkdir -p /dev/net vzctl exec 55716 mknod /dev/net/tun c 10 200 vzctl exec 55716 chmod 600 /dev/net/tun