Jochen Bern <[email protected]> writes:

> I suppose that one could configure nginx so as to offer a
> password(?)-protected HTTP CONNECT to the OpenVPN server, and tell the
> client-side OpenVPN to use that as a proxy.

That is sort of what I was thinking, but was hoping someone had already
worked this out and posted how to do it.

> *Or* you could use --bind to make the client use a specific *source*
>  port, hoping that it won't get SNATed away on the Internet uplink,
>  and use that "identifier" and iptables rules so as to have "home
>  base" DNAT the connection to the OpenVPN server instead of the nginx

My belief is that source ports will rarely survive, especially on the
kinds of networks where you need to get around blocking.



_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to