Displaying 20 results from an estimated 2000 matches similar to: "multiple ssh tunnels needing different rules"
2003 Aug 13
3
a solution to pppd random interface name ?
Hi,
I have multiple ppp interfaces that does not correspond to the same
network usage. Do you know anything about trying to set definitively the
ppp+ name ? or anything to adapt automagically iptables to the real
network which is behind each ppp+ interface ?
I''ve tooken a look into the IFNAME env var... but it doesn''t seems to
work :c/
regards,
--
BeTa
2005 Jun 26
12
Vpn Trouble
I am trying shorewall as my previous post With alisias on eth1 loc and 4
pptp client vpns.
The odd thing is when I enter one of the vpns in interfaces such as vpn1 it
works.
But if I enter the vpn in the hosts file shorewall blocks the vpns.
shorewall/hosts
#ZONE HOST(S) OPTIONS
loc eth1:192.168.25.0/24
loctw eth1:192.168.50.0/24
locsa eth1:192.168.75.0/24
vpntw
2005 Mar 25
3
small issue with eth0:1
breakdown of what iam doing
ok i have access to 6 ips and i want to run all of them through my
firewall
ifconfig eth0 209.159.32.162 netmask 255.255.255.0 up
ifconfig eth0:1 209.159.32.163 netmask 255.255.255.0 up
that sets up the network card to have 2 address well in shorewall i
tried to add
eth0:1 to my interfaces well it says that
Determining Zones...
Zones: inet inet2 loc cust vpn1
2004 Dec 11
5
Problem report -- shorewall 1.4
Hello list,
I wish to report a problem with openvpn tunnels.
Synopsis: Despite adding policies to the shorewall policy file, I have
to add extra rules to allow the UDP port 5000 packets to get through.
I have used no particular setup guide.
I believe this problem goes away with shorewall 2.0.9, as I have
implemented openvpn with that version on a different machine, and I see
no UDP:5000 packet
2015 Sep 25
1
tinc initialization (in both Red Hat and Debian families)
Hello again,
>From the point of view of a Red Hat *user*, the standardised way of doing
things would be to have
an /etc/sysconfig/tinc file containing something like:
NETWORKS="vpn1 vpn2 vpn3" (one or more names separated by spaces)
At initialization, each name should launch a separate tinc instance (a
different VPN)
tinc service should not start until the user adds at least
2017 May 01
4
How to set Subnet in a node which act as both server and client role?
Hi, Tinc experts
Diagram as below, A is trying to access host X behind C:
A >> B >> C — “host X"
B is the tinc server for A, but also B is the tinc client to connect to C.
My question is, if I only use one VPN (/etc/tinc/myvpn), then the host configuration for B will be tricky.
As the tinc server to A, B’s host config (/etc/tinc/myvpn/hosts/B) needs have the Subnet = X/32,
2017 May 01
2
How to set Subnet in a node which act as both server and client role?
Hi, Etienne
In addition, is there any option or switch can turn of the automatic direct connection? For the example below, even A has the route to C and can establish UDP connection directly, but I need the traffic to go through B, how can I achieve that easily? (instead of remove something from A’s routing table, or manually block the connection between A and C)
> On 1 May 2017, at 6:28 PM,
2017 May 01
1
How to set Subnet in a node which act as both server and client role?
There is no concept of "client" or "server" in tinc. tinc is purely
peer-to-peer. "ConnectTo" statements only indicate which node will attempt
to establish the initial connection, but once the connection is
established, direction does not matter.
It is unclear from your message which node is responsible for which subnet.
If X/32 truly belongs to C, then simply set
2007 Jul 06
8
interop with strongswan / ipsec
I see support in shorewall for the KAME-tools, how about strongswan ?
I have setup shorewall 3.4.4 and strongswan 4.1.3, making this my
vpn-gateway for the subnet behind it.
# Shorewall version 3.4 - Zones File
#ZONE TYPE OPTIONS IN OUT
# OPTIONS OPTIONS
fw firewall
fil ipsec mode=tunnel mss=1400
net ipv4
2004 Aug 04
3
should I shape tun[N] or eth0 ?
Greetings,
me again. I''m starting to feel miff now.
If I have a few vpn tunnels with different tun interfaces. And all this tunnel
traffic is coming in on my eth0 interface, it also leave via eth0 again. I
would like to share the available bandwidth evenly with tunnel clients. Would
applying the bandwidth rule on eth0 with htb & sfq work for sharing the
bandwidth or will
2017 May 01
1
How to set Subnet in a node which act as both server and client role?
Hi, Etienne
I took a look for the below host configuration parameter (IndirectData), the default is no. For the below example:
A ConnectTo B, B ConnectTo C:
If IndirectData = no (default), then A wouldn’t establish direct connection with C, but will be forwarded by B.
If IndirectData = yes, then A will try to establish direct connection with C, even though A don’t have the statement of
2004 Nov 17
20
Some DNAT''s work, some don''t
We''ve just upgraded to a new firewall machine, and a new version of
Shorewall. We''re now on 2.04; previous version was 1.3.9b (!). So I''m
pretty sure whatever problems we''re having are related to the big
version jump.
We''re using config files that exactly match our old (working)
configuration (IOW, these are things which _were_ working on the old
2008 Jan 31
3
Controling vpn access
Hí everybody, you have a nice day.
I am configuring accounting in shorewall /etc/shorewall/accounting and
the traffic between eth0 (local network)1, eth2(local network2) and
eth3(local network3) <--> eth1(ip public network), works fine. I
make the accounting because y want to control the remote vpn
access(pptpd) throught shorewall.
Which is the way to control vpn /ip/access in
2012 Dec 29
10
How could I open Port 1701 for VPN l2tp/ipsec
Hello Mailinglist,
please excuse my bad english - but I am not a native speaker.
My Network looks like this:
Internet --- dyn. IP --- Firewall (shorewall) --- LAN (192.168.X.X)
No I try to connect my iphone (from mobile Internet G3) over VPN
(l2tp/ipsec) with the firewall.
But I can´t open the necessary Port 1701.
/var/log/syslog
...
Dec 30 00:24:29 router kernel: [226128.293757]
2017 May 01
1
How to set Subnet in a node which act as both server and client role?
You’re talking about Layer 2 bridging by Tinc? The use case here is layer 3 routing, but anyway, thanks for your feedback.
> On 1 May 2017, at 8:09 PM, LowEel <loweel at gmx.de> wrote:
>
> I cannot understand why you say the configuration for B will be tricky.
>
> If you select the switch mode, and some machine can initiate a
> connection to some other machine, until
2004 Nov 01
1
2 external Interfaces and dozens of tunnels to MASQ
I have a firewall with 2 connections to the internet (eth1 and eth2) and
one LAN interface. on the LAN interface, the users can connect via PPTP.
those authenticating via pptp shall be masqueraded over eth2, those not
authenticating should be ordinary masqueraded over eth1. as from the
archives I took the configuration like in FAQ32, but this doesn''t work
with the ppp+ interfaces. I
2004 Oct 23
9
OpenVPN tunnel question
Hi,
I am new to VPN an OpenVPN with shorewal. I tryed a lot and read a
bounch of howto''s but nothing helped so I came here.
I want to tunnel all request to my server 141.48.XXX.XXX from my home
network throu port 443.
I want to do this because this is the only way I can connect to my
server using ssh or ony other tool or port. On Port 80 Apache is
running, so I only have the https port
2004 Dec 14
1
openvpn/shorewall tunnel problem
Dear list,
I am having a problem with openvpn. I have the following arrangement,
running two instances of openvpn on "home fw". I want to protect my
WLAN in back of the home fw and that works fine. I can see "Peer
connection initiated with 192.168.1.3:5000" in daemon.log on homefw.
Nothing gets initiated with officefw, nor can I ping the other end of
the tunnel at officefw.
1998 Oct 03
1
Serius cross-subnet browsing question
> I've been having troubles getting cross subnet browsing working in
> existance with a WinNT domain master (hey, it's not my machine).
> Basically what is happening is that I am trying to setup a VPN (which
> shouldn't complicate things) that browsing will work across. The idea is
> this:
>
> There is an office in my local city that I'm connecting San
2008 Jul 06
3
Routing and keying Questions
Hello!
I use tincd to interconnect 3 LANs: A, B and C. So long, it works fine:
everybody reaches everybody. But I want a different behavior: A and B should
be allowed to talk, as should B and C. I tried to simply delete the
host-files on the nodes that should not be allowed to talk to eachother:
A has a hostfile from B
B has a hostfile from A and C
C has a hostfile from B
But this is no