Tema: Re: HELP! OpenVPN
Autorius: Dex
Data: 2009-01-26 19:16:39
bandyk firewall'a nuimti (viska leisti) ir paziurek, ar tada eis pinginti.
imho cia pas tave su firewall'u beda.


Pluss wrote:
> Tiesa, dar truputi praleidau:
> 
> iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
> iptables -A INPUT -i tun+ -j ACCEPT
> iptables -A FORWARD -i tun+ -j ACCEPT
> iptables -A INPUT -i tap+ -j ACCEPT
> iptables -A FORWARD -i tap+ -j ACCEPT
> 
> 
> 
> Pluss wrote:
>> Kas susije su OpenVPN ir Firewall, tai pas mane stai kas:
>>
>> $IPTABLES -A ovpn -m state --state INVALID -j DROP
>> $IPTABLES -A ovpn -m state --state ESTABLISHED,RELATED -j ACCEPT
>> $IPTABLES -A ovpn -s AAA.BBB.CCC.DDD -m state --state NEW -j ACCEPT
>> $IPTABLES -A ovpn -m limit --limit 10/second -j LOG  --log-level 
>> warning --log-prefix "OpenVPN-DROP "
>> $IPTABLES -A ovpn -j DROP
>>
>> $IPTABLES -A INPUT -d $ExtIP -p UDP --dport 1194 -j ovpn
>> $IPTABLES -A INPUT -d $ExtIP -p TCP --dport 1194 -j ovpn
>>
>>