Author Topic: 3.3 OpenVPN + firewall  (Read 2015 times)

logdog

  • Zen Hero
  • *****
  • Posts: 623
  • Karma: +29/-2
    • View Profile
3.3 OpenVPN + firewall
« on: January 08, 2014, 03:32:03 pm »
hi2all

I can not block access from 192.168.160.2 to the terminal server 10.0.0.4
I need to 192.168.160.2 - block, and for 192.168.160.4 - resolved.

Network diagram
http://floomby.ru/s1/xWWtm4

Configuration VPN
http://floomby.ru/s1/HWW8dU
http://floomby.ru/s1/aWW8d2

Firewall - Filtering rules for internal networks
vpn.jpg

This's a bug or my fault?

ps: sorry for my english.
« Last Edit: March 15, 2014, 07:48:55 pm by logdog »

logdog

  • Zen Hero
  • *****
  • Posts: 623
  • Karma: +29/-2
    • View Profile
Re: 3.3 OpenVPN + firewall
« Reply #1 on: March 15, 2014, 07:53:02 pm »
up (

ismaelnoble

  • Zen Apprentice
  • *
  • Posts: 10
  • Karma: +0/-0
    • View Profile
Re: 3.3 OpenVPN + firewall
« Reply #2 on: March 16, 2014, 01:29:14 am »
So having a firewall rule 'deny 192.168.160.2 all to 10.0.0.4' does not work...if u really need to block access to a VPNed system but not another on the same network sounds like an inefficient way to do things. Maybe u should have 2 VPN servers running on the zentyal. One can have access to ur terminal server and the other does not

logdog

  • Zen Hero
  • *****
  • Posts: 623
  • Karma: +29/-2
    • View Profile
Re: 3.3 OpenVPN + firewall
« Reply #3 on: March 16, 2014, 09:46:42 am »
Maybe u should have 2 VPN servers

if I need to block access to the domain server 10.0.0.6 - 3 vpn servers, something else to block - n-vpn servers ....
I think - it is wrong to create as many vpn servers, but even if I create a vpn servers, how to allow access оn 10.0.04 only 1 port blocked (10.0.0.4:3389)?
« Last Edit: March 16, 2014, 09:50:40 am by logdog »