|
|||
Change block all to block log all and reload your rule set.
Now all blocked packets by will show up on the pflog(4) interface. To see these packets as root do: # tcpdump -n -e -ttt -i pflog0
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump |
|
|||
I don't use openVPN but is that connection attempt to port 443 trying to establish the VPN connection? That happens over the external interface, not the tunnel (since it needs to connect to set up the tunnel). You need to allow that on ure0.
|
|
||||
Thanks for the advice, but it turns out the problem was a typo! (isn't it always?)
Code:
# ue0 is regular internet # tun0 is OpenVPN block all # allow local ssh connections pass proto tcp from ue0:network to port ssh # DNS (for server IP lookup) pass quick proto {tcp, udp} from any to any port 53 keep state # VPN IPs pass out on ure0 proto {tcp, udp} from any to { 185.117.118.24, 185.117.118.23 } pass on tun0 all Code:
[ VPN is running in another screen ($ sudo openvpn server.ovpn) ] $ ping www.google.com PING www.google.com (172.217.167.100): 56 data bytes 64 bytes from 172.217.167.100: icmp_seq=0 ttl=112 time=559.999 ms 64 bytes from 172.217.167.100: icmp_seq=1 ttl=112 time=558.409 ms 64 bytes from 172.217.167.100: icmp_seq=2 ttl=112 time=558.484 ms [ I ctrl-c OpenVPN in the other screen ] ping: sendto: Permission denied ping: sendto: Permission denied ping: sendto: Permission denied |
Tags |
openvpn, pf, vpn |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
OpenVPN on OpenBSD 5.1 | scrummie02 | OpenBSD Security | 6 | 1st October 2012 04:46 PM |
Does pf conflict with OpenVPN? | Emile | OpenBSD Packages and Ports | 37 | 2nd February 2011 11:03 PM |
Cannot set up OpenVPN | guitarscn | OpenBSD Security | 8 | 5th October 2009 05:19 PM |
SSH tunneling vs. OpenVPN | revzalot | OpenBSD Security | 8 | 31st May 2009 06:45 AM |
OpenVPN management | bichumo | General software and network | 0 | 15th July 2008 09:05 AM |