[Openvpn-users] Fwd: Introducing the OpenVPN Data Channel Offload Windows driver

2021-05-05 Thread Lev Stipakov
Hello all, I would like to announce a new version of "ovpn-dco-win"-enabled client. Here are some changes from the previous version: 1) MSI based installer. This makes upgrades from existing installations more smooth, since starting from version 2.5 openvpn has switched to MSI. - ovpn-dco-win

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-05 Thread Jan Just Keijser
Hi, On 05/05/21 01:20, Bo Berglund wrote: On Sun, 2 May 2021 19:17:26 +0200, Gert Doering wrote: Now, for "client A talks to client B", there's a catch - if you put "client-to-client" into the openvpn server config, OpenVPN will forward the packets directly, bypassing tun0 firewalls. Without

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-05 Thread Bo Berglund
On Wed, 5 May 2021 08:03:12 +0200, Gert Doering wrote: >Hi, > >On Wed, May 05, 2021 at 01:20:14AM +0200, Bo Berglund wrote: >> But I don't want any other traffic to go through the VPN, so how should I set >> the server conf file to accomplish that? > >If the server conf (and client conf) has no i

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-05 Thread Gert Doering
Hi, On Wed, May 05, 2021 at 11:28:13AM +0200, Bo Berglund wrote: > >> server 10.8.113.0 255.255.255.0 'nopool' > >> ifconfig-pool 10.8.113.2 10.8.113.127 255.255.255.0 > > > >This is a bit weird. "server" *without* "nopool" will include the > >pool setting (though for the full /24)... so this is

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-05 Thread Bo Berglund
On Wed, 5 May 2021 13:17:58 +0200, Gert Doering wrote: >I was more thinking about "if someobody malicous lays their hand on such >an openvpn client config" - then you might want to do extra precautions >on the server to stop them from reaching "anything that is not on the VPN". > >If it's all und