Old 03-30-2009, 10:11 AM   #11 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,698
sky-knight is on a distinguished road
Default

config -> administration -> public address

Select use manually specified IP, and fill in the WAN IP address.

Alternately on the same screen is the use hostname option. The hostname is configured on config -> networking -> hostname. The TOP field. That name needs to be publicly resolvable, and then the hostname will go into the scripts instead.

6 of one, half dozen of the other. Personally I prefer hostnames, easier to remember.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 03-30-2009, 10:19 AM   #12 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

check under administration, public address and see what you have there..
andrew50 is offline  
Old 03-30-2009, 10:21 AM   #13 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

Ok that was wrong. I changed it to the DNS name for the WAN. I'm going to guess my next step is to reexport and try again.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 01:42 PM   #14 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

Ok progress. The client is now connected and can ping the gateway on my network 10.250.4.1, and the Untangle server at 10.250.4.12, but nothing behind the Untangle gateway.

Any pointers where to look why this will not go through?
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 01:47 PM   #15 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

do you have the firewall set to block all ?

probably need to make a rule for VPN to be allowed to Internal
andrew50 is offline  
Old 03-30-2009, 01:54 PM   #16 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

Firewall passes 25,21,80,443 to 10.250.4.6. That's been working since I started.There is no block all, and the logs do not show a firewall connection being dropped.

Tracert from the client goes to 172.16.0.1 and then dies out.

I put a rule in that 172.16.0.9 allowed inbound. Not showing up in the logs either.

I do really appreciate your time here.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 01:57 PM   #17 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

I just noticed, that I can FTP to 10.250.4.6 from the client, so it has to be something from the firewall. Source address is 172.16.0.9.

I'm assuming I should allow 172.16.0.9 to pass through the firewall completely.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 02:01 PM   #18 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
The VPN interface is "less trusted" and if you have the firewall module installed. You're supposed to have to define rules on what traffic you want passed.
passing traffic from external to internal is different than VPN to internal
andrew50 is offline  
Old 03-30-2009, 02:03 PM   #19 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

for funsies try making a firewall rule that allows all VPN to all internal and tighten from there as needed if it works
andrew50 is offline  
Old 03-30-2009, 02:04 PM   #20 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

Code:
Enable Rule: Check Yes
Description:Allow VPN FULL ACCESS
Action: PASS
Log: up to you
RuleTraffic Type:ANY
Source Interface:VPN
Destination Interface:INTERNAL
Source Address:ANY
Destination Address:ANY
Source Port:ANY
Destination Port:ANY
andrew50 is offline  
Closed Thread

Tags
openvpn, remote network

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:15 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0