Author Topic: Access Ebox from VPN  (Read 1552 times)

aka_gyt

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Access Ebox from VPN
« on: April 22, 2010, 08:18:36 pm »
Hello!
ebox 1.4.3
firewall rulles allow all traffic (in all rules set any to any)
wan eth0
local eth1 192.168.100.253
vpn tap0   192.168.160.1
from local network i can access to any service on ebox, but not from vpn clients




aka_gyt

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: Access Ebox from VPN
« Reply #1 on: April 23, 2010, 12:09:07 pm »
Firewall log shows dropped packets:
in interface: tap0
out interface:
source: 192.168.160.2
destination: 192.168.160.1
protocol: tcp
source port: 65365
destination port: 3128

How it is possible to correct?

B_Khuwera

  • Zen Monk
  • **
  • Posts: 51
  • Karma: +0/-1
    • View Profile
Re: Access Ebox from VPN
« Reply #2 on: April 23, 2010, 04:04:35 pm »
Der aka_gyt

Try using the DDNS service .. and access the management GUI from Firefox browser.

note : dont forget to create firewall rule to enable access to ebox web management from outside.

Regards

aka_gyt

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: Access Ebox from VPN
« Reply #3 on: April 24, 2010, 12:42:44 pm »
Der aka_gyt

Try using the DDNS service .. and access the management GUI from Firefox browser.

note : dont forget to create firewall rule to enable access to ebox web management from outside.

Regards
i can access from internal, external but not from vpn network...

B_Khuwera

  • Zen Monk
  • **
  • Posts: 51
  • Karma: +0/-1
    • View Profile
Re: Access Ebox from VPN
« Reply #4 on: April 26, 2010, 10:08:49 am »
Dear aka_gyt

Seems the firewall is blocking proxy access from outside, check filter from external to ebox on firewall menu. ebox seems look the 192.168.160.xxx to be external.
add the port 3128 to allow access. but this means fully open port 3128 to outside world, please be carefull  Hope this help.

Regards


aka_gyt

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: Access Ebox from VPN
« Reply #5 on: April 27, 2010, 06:38:56 pm »
fixed by adding

tun-mtu 1200
fragment 1200
mssfix

to openvpn config

Javier Amor Garcia

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1225
  • Karma: +12/-0
    • View Profile
Re: Access Ebox from VPN
« Reply #6 on: April 28, 2010, 12:21:23 pm »
Don't use the VPN address to coneect. You should use the inteernal interface addresses instead