Results 1 to 6 of 6
  1. #1
    Untangle Ninja Solignis's Avatar
    Join Date
    Jul 2008
    Location
    Hudson, Ohio, USA
    Posts
    1,693

    Default In a bind with BIND9

    I having a problem with OpenVPN when I try to query my BIND9 server(s).

    I have an option in my BIND config that restricts querying ability to what is defined in the ACL lists in the config file.

    The problem I am having is OpenVPN has an ACL entry but it is not allowing it though with the IP information I have given it.

    The ACL is for 172.16.0.0/24 which is my OpenVPN subnet. But it appears my computer when talking back to the network after the vpn is established is using a /30 subnet mask which throws off my acl. I tried making an acl with the same address but a /30 and it did no good.

    Anyone got any idea of how I can work around this?
    “Most good programmers do programming not because they expect to get paid or get adulation by the public, but because it is fun to program.” - Linus Torvalds

  2. #2
    Master Untangler jcoehoorn's Avatar
    Join Date
    Mar 2010
    Location
    York, NE
    Posts
    607

    Default

    I know it's hackish, but what about two acl entries?
    Four time Microsoft ASP.Net MVP managing an IBM System x3250 / X3440 / 8GB with Untangle 9.4 to protect 40Mbits for 450+ residential college students and associated staff and faculty

  3. #3
    Untangle Ninja mrunkel's Avatar
    Join Date
    Jul 2008
    Posts
    2,989

    Default

    Huh? How does the BIND server know what subnet mask the computer is using? That information isn't transmitted.

    Maybe I'm misunderstanding.
    m.


    Big Frickin Disclaimer:
    While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

    It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  4. #4
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,914

    Default

    Mask is used to indicate a range in this case.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  5. #5
    Untangle Ninja mrunkel's Avatar
    Join Date
    Jul 2008
    Posts
    2,989

    Default

    Quote Originally Posted by sky-knight View Post
    Mask is used to indicate a range in this case.
    Clearly, but that doesn't explain anything about why the client net mask matters.
    m.


    Big Frickin Disclaimer:
    While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

    It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  6. #6
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,914

    Default

    That would be because Solignis doesn't understand why the mask works as a range. He's got an OpenVPN connection, which uses a /30 mask on the client, but doesn't apparently understand that the entire range is still represented by the /24 range he originally put in.

    In short, what he's describing doesn't matter and he's having a different issue entirely.

    The only reason I know this, is I've worked with him before so I've come to be able to decipher his brand of confusion. Which is rather scary to be honest.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2