Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread Jan Just Keijser
Hi, On 01/05/21 11:03, Gert Doering wrote: On Fri, Apr 30, 2021 at 09:15:07PM +, tincantech via Openvpn-users wrote: Ref: https://forums.openvpn.net/viewtopic.php?f=6&t=32193#p99021 (This also applies to --http-proxy) The question is, how/what does openvpn do in the case that the client i

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread Gert Doering
Hi, On Mon, May 03, 2021 at 12:01:04PM +0200, Jan Just Keijser wrote: > > I would expect this to do the same thing it would do for the "non proxy" > > case - install a host route to the existing default gateway so packets > > to the server (and with proxy, to the proxy) can still flow. Then, > >

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread Jan Just Keijser
Hi, On 03/05/21 12:12, Gert Doering wrote: On Mon, May 03, 2021 at 12:01:04PM +0200, Jan Just Keijser wrote: I would expect this to do the same thing it would do for the "non proxy" case - install a host route to the existing default gateway so packets to the server (and with proxy, to the prox

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-03 Thread lejeczek via Openvpn-users
On 03/05/2021 02:35, Kenneth Porter wrote: --On Sunday, May 02, 2021 4:02 PM +0100 lejeczek via Openvpn-users wrote: Not being an expert I expected that, on a Linux box, I can firewall 'tun0' of ovpn server. Using 'firewalld' it put 'tun0' into a dedicated zone and selected a few ports f

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread Gert Doering
HI, On Mon, May 03, 2021 at 12:38:21PM +0200, Jan Just Keijser wrote: > >> and that does not seem to take any proxy hosts into account. > > But "link_socket_current_remote" is very likely to be "whoever we are > > talking to right now", aka "the proxy". > > > you're absolutely right, Sometimes o

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Monday, 3 May 2021 11:43, Gert Doering wrote: > HI, > > On Mon, May 03, 2021 at 12:38:21PM +0200, Jan Just Keijser wrote: > > > > > and that does not seem to take any proxy hosts into account. > > > > But "l

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-03 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Monday, 3 May 2021 11:39, lejeczek via Openvpn-users wrote: > On 03/05/2021 02:35, Kenneth Porter wrote: > > > --On Sunday, May 02, 2021 4:02 PM +0100 lejeczek via > > Open

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread Gert Doering
Hi, On Mon, May 03, 2021 at 12:52:22PM +, tincantech wrote: > My initial question was: > > Does --redirect-gateway do the same for --socks-proxy/--http-proxy > as it does for --remote? Install a route for the server we are connected > to so that address is not routed into the tunnel. So the

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Monday, 3 May 2021 14:00, Gert Doering wrote: > Hi, > > On Mon, May 03, 2021 at 12:52:22PM +, tincantech wrote: > > > My initial question was: > > Does --redirect-gateway do the same for --socks-proxy/--