Hello,

Am 01/08/2016 um 10:29 AM schrieb ValdikSS:
> Hi.
> 
> On 01/07/2016 09:19 PM, Jan Lühr wrote:
>> But ... this doesn't seem to do the trick. - If a hotel wifi
>> network is using 2001:470:5093:3::/64 for auto configuration -
>> traffic will leak, since /64 is more specific, than /48 - right?
> 
> How could this be? Are you assuming that the attacker could set up
> rogue wi-fi ap with the same IP ranges just as you use inside the
> VPN? How is that different from IPv4 then?

You're right. I'ven't thought this, yet.

>> - How does this make sure, that the client is using the VPN for
>> _all_ uplink traffic?
> 
> Use firewall.

Well... this is kind of obvious :) - but the rules are non-trivial for
me. Thus I'm asking for a working config. Can you provide some?

Thanks,
Jan

------------------------------------------------------------------------------
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to