On Wed, Jun 14, 2017 at 05:25:37PM -0400, Pippin1st via Openvpn-users wrote:
> Hello,
> 
> > When thinking about firewalls (and routing, for that matter), imagine
> > OpenVPN as a black box sitting on a "second network card" connected
> > to the linux machine.
> 
> > So there's iptables on the tun interface connecting "linux networking"
> > and "openvpn black box" - packets towards openvpn (and the other side
> > of the VPN) are processed "out on tunX", while packets coming from
> > the VPN are processed "in on tunX".
> 
> That`s how the picture looked in my mind the first time and made the
> first diagram. Then changed it twice to correct the order of
> comp/frag/enc. and traffic NOT passing routing & iptables
> from OpenVPN to tun and back.

Your previous picture was correct..

I clarified with Gert on IRC because he did not realize that my comments
were about your specific diagram, but he thought I was generally stating
how the big picture of OpenVPN works (including remote hosts etc..).

Cheers,


-- 
Antonio Quartulli

Attachment: signature.asc
Description: Digital signature

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to