Old 03-30-2009, 02:07 PM   #21 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

The choices for source interface are, External, DMZ, Internal, Less trust, More Trusted. I have a rule that allows Source Less trusted destination any source IP 172.16.0.9 (the remote IP) and destination IP any, traffic type any. No dice.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 02:08 PM   #22 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

That's got to be the problem, that I don't have VPN as source interface.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 02:24 PM   #23 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

A radical idea... I rebooted untangle and got the option on the source interface.
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 02:27 PM   #24 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

crap, that is usually one of my first sugesstions along with power cycling the item in the rack...I posted it in another thread this morning, but not here.

and then ?
andrew50 is offline  
Old 03-30-2009, 02:54 PM   #25 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

Ok. Think this is resolved with your AWESOME help.

Solution was making the gateway the untangle server. Dude, I feel like I should buy you a beer
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-30-2009, 03:11 PM   #26 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default



glad I could help!
andrew50 is offline  
Old 03-30-2009, 03:28 PM   #27 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,698
sky-knight is on a distinguished road
Default

You shouldn't ever make a UT bridge the gateway. The fix is to define a static route for the OpenVPN address pool, and remote subnets on the other side of the site-to-site tunnel, in your router.

Also, as for ping... UT's packet filter by default prevents all ICMP traffic. So ping will never work unless you kick the packet filter.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 03-30-2009, 03:47 PM   #28 (permalink)
Untanglit
 
windozeuser's Avatar
 
Join Date: Mar 2009
Posts: 21
windozeuser is on a distinguished road
Default

sky-knight i'd like to briefly discuss about the UT bridging the gateway. I have a large deployment coming up and part of this is evaluating untangle as a solution.

do you mean the untangle should never be put directly behind a firewall?
__________________
An unspecified error has occurred in module <UNKNOWN>. Please contact your system administrator and tell him you are being used a beta tester.
windozeuser is offline  
Old 03-31-2009, 09:52 AM   #29 (permalink)
Master Untangler
 
Join Date: Mar 2008
URLs submitted: 6
Posts: 143
andrew50 is on a distinguished road
Default

Quote:
Originally Posted by windozeuser View Post
sky-knight i'd like to briefly discuss about the UT bridging the gateway. I have a large deployment coming up and part of this is evaluating untangle as a solution.

do you mean the untangle should never be put directly behind a firewall?
I believe he means a bridged untangle should not be the gateway, but the device on the other side of it should be..
andrew50 is offline  
Old 03-31-2009, 11:10 AM   #30 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,698
sky-knight is on a distinguished road
Default

Yes, UT in bridge mode isn't setup to be a gateway of anything. If you make it the gateway you will "fix" OpenVPN at the expense of breaking everything else. You need to configure your routing equipment responsible for each segment for the VPN links.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Tags
openvpn, remote network

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:15 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0