Networking Forums

Networking Forums > Computer Networking > Linux Networking > openvpn and ethernet-bridge on firewall/gateway server

Reply
Thread Tools Display Modes

openvpn and ethernet-bridge on firewall/gateway server

 
 
Ole
Guest
Posts: n/a

 
      11-09-2005, 02:00 PM
Hello,

i'm setting up a vpn server (OpenVPN) on a firewall/proxy server.

Operating Systems are Windows XP on the clients and Suse Linux 9.0 pro
(kernel 2.4.21) on the firewal/proxy. Vpn software is OpenVPN 2.0.2.

I plan to use the bridged mode in order to simplify the routing setup.

The question i have is as follows:

When i bridge the tap-device (used by OpenVPN) with the internal NIC of
the firewall/gateway server, the ip addresses of the original internal
NIC and that of the tap-device vanishes and the br0-device (the bridge)
gets the ip address the internal NIC was assigned originally.

How does this affect the firewall/proxy in its original functionality?
Is it necessary to install another NIC, to have one for the vpn traffic
and another for
the standard traffic (Website access from inside the network, mail
transfer etc.) ?

Any field reports are highly appreciated.

Thanks in advance
sincerely yours
Ole

 
Reply With Quote
 
 
 
 
Steve Horsley
Guest
Posts: n/a

 
      11-11-2005, 06:48 PM
Ole wrote:
> Hello,
>
> i'm setting up a vpn server (OpenVPN) on a firewall/proxy server.
>
> Operating Systems are Windows XP on the clients and Suse Linux 9.0 pro
> (kernel 2.4.21) on the firewal/proxy. Vpn software is OpenVPN 2.0.2.
>
> I plan to use the bridged mode in order to simplify the routing setup.
>
> The question i have is as follows:
>
> When i bridge the tap-device (used by OpenVPN) with the internal NIC of
> the firewall/gateway server, the ip addresses of the original internal
> NIC and that of the tap-device vanishes and the br0-device (the bridge)
> gets the ip address the internal NIC was assigned originally.
>
> How does this affect the firewall/proxy in its original functionality?
> Is it necessary to install another NIC, to have one for the vpn traffic
> and another for
> the standard traffic (Website access from inside the network, mail
> transfer etc.) ?
>
> Any field reports are highly appreciated.
>
> Thanks in advance
> sincerely yours
> Ole
>


This sounds dangerous to me. I could be wrong, and would welcome
advice from someone who knows better, but I have the feeling that
the bridging goes on underneath the level of iptables, so that in
effect, you VPN clients are bridged directly onto the LAN with no
firewall in between. And iptables can only control access to/from
the server part of the PC. Now, it may be possible to set up some
filtering for the bridging function, but I am not aware of such a
capability.

Steve
 
Reply With Quote
 
Tauno Voipio
Guest
Posts: n/a

 
      11-11-2005, 07:00 PM
Steve Horsley wrote:
> Ole wrote:
>
>> Hello,
>>
>> i'm setting up a vpn server (OpenVPN) on a firewall/proxy server.
>>
>> Operating Systems are Windows XP on the clients and Suse Linux 9.0 pro
>> (kernel 2.4.21) on the firewal/proxy. Vpn software is OpenVPN 2.0.2.
>>
>> I plan to use the bridged mode in order to simplify the routing setup.
>>
>> The question i have is as follows:
>>
>> When i bridge the tap-device (used by OpenVPN) with the internal NIC of
>> the firewall/gateway server, the ip addresses of the original internal
>> NIC and that of the tap-device vanishes and the br0-device (the bridge)
>> gets the ip address the internal NIC was assigned originally.
>>
>> How does this affect the firewall/proxy in its original functionality?
>> Is it necessary to install another NIC, to have one for the vpn traffic
>> and another for
>> the standard traffic (Website access from inside the network, mail
>> transfer etc.) ?
>>
>> Any field reports are highly appreciated.
>>
>> Thanks in advance
>> sincerely yours
>> Ole
>>

>
> This sounds dangerous to me. I could be wrong, and would welcome advice
> from someone who knows better, but I have the feeling that the bridging
> goes on underneath the level of iptables, so that in effect, you VPN
> clients are bridged directly onto the LAN with no firewall in between.
> And iptables can only control access to/from the server part of the PC.
> Now, it may be possible to set up some filtering for the bridging
> function, but I am not aware of such a capability.
>
> Steve


There are filtering possibilities resembling those of iptables
for the data link layer (bridging), Google for ebtables.

IMHO, for security, filtering at the network layer by iptables
is easier to administer correctly, so if there is no absolute
need to do a data-link layer OpenVPN connection (via tap0), please
use a routed version instead (via tun0).

--

Tauno Voipio
tauno voipio (at) iki fi
 
Reply With Quote
 
Steve Horsley
Guest
Posts: n/a

 
      11-11-2005, 09:59 PM
Tauno Voipio wrote:
>
> There are filtering possibilities resembling those of iptables
> for the data link layer (bridging), Google for ebtables.


Thank you.

Steve
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
need help using openvpn to bypass corp firewall wild98@gmail.com Linux Networking 6 05-16-2007 01:25 AM
Network briding on gateway machine for openvpn David Linux Networking 1 03-14-2007 10:10 AM
openvpn server bridge. music Linux Networking 19 02-16-2007 07:14 AM
Buying Advice - ADSL Router, Ethernet, Wireless, Modem, Firewall Gateway M Broadband 9 10-17-2005 09:24 PM
problem setting up moto we800g ethernet bridge with linksys ethernet router I'm NOT DON Windows Networking 0 05-30-2005 07:50 PM



1 2 3 4 5 6 7 8 9 10 11