Unix/Linux Go Back    


Security Discuss UNIX and Linux computer and network security, cyber security, cyber attacks, IT security, and more.

Openvpn nat and iptables

Security


Tags
iptables, vpn

Reply    
 
Thread Tools Search this Thread Display Modes
    #1  
Old Unix and Linux 11-04-2016
end end is offline
Registered User
 
Join Date: Nov 2016
Last Activity: 8 November 2016, 1:09 PM EST
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Openvpn nat and iptables

good day good people

hi

first to tell that firewall and vpn is working as expected, but I notice something strange.

I have host system 11.11.11.11(local ip) firewall is blocking everything except port to vpn.
I have vpn on virtualized system 22.22.22.22 (CentOS both host and virtual). They are behind MikroTik router and then to my ISP router. This is a home setup I'm just experimenting.

PREROUTING 11.11.11.11:1194 to 22.22.22.22:1194 all other is blocked by iptables.
POSTROUTING 22.22.22.22 to 11.11.11.11

I noticed with Wireshark from host 11.11.11.11 that while I'm connected to vpn from another pc that 11.11.11.11 is connecting to ip addresses of websites I visit while in same time is connected to vpn. like:

11.11.11.11 XX.XX.XX public ip
11.11.11.11 tcp udp sites i visit

but 11.11.11.11 is unnecessarily making connections to website ip addresses. She cannot make the reqests because DNS and ports for that are blocked. So this is because postrouting command my best guess. Can this somehow be disabled? First this is a security issue, second its unnecessary.

Someone told me that this is because NAT setup. but I believe that this can be disabled somehow, I didn't find solution yet so maybe someone know how.

thanks


Moderator's Comments:
Openvpn nat and iptables We had to correct a lot of spelling errors. Please put more effort into using proper english

Last edited by Scrutinizer; 11-05-2016 at 03:48 AM.. Reason: Spelling
Sponsored Links
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Linux More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
OpenVPN and NAT nickb1976 Solaris 0 08-05-2015 04:27 PM
iptables for openvpn sdnix UNIX for Dummies Questions & Answers 0 08-15-2014 12:38 PM
iptables in a NAT scenario capri_guy84 Security 1 05-17-2013 04:12 PM
NAT Loopback and iptables 6765656755 Red Hat 0 04-07-2013 11:18 AM
Iptables/TC: how to make masqueraded traffic go through an openVPN tun0? theVOID IP Networking 2 08-27-2008 11:46 PM



All times are GMT -4. The time now is 09:42 PM.