Re: Shorewall with OpenVPN Hub and Spoke

Tuomo Soini via Shorewall-users <[email protected]> Thu, 28 Nov 2024 10:15:11 +0200
Newsgroups gmane.comp.security.shorewall
Organization Foobar Oy
Message-ID <[email protected]>
On Thu, 28 Nov 2024 06:47:47 +0000
simonseys via Shorewall-users <[email protected]>
wrote:

> So basically routeback is behaving like client-to-client would
> allowing inter-client communication unfettered by Shorewall. Why is
> routeback not having the desired effect of allowing me firewall
> traffic that is arriving and leaving on my vpn zone interface?

You can change this behaviour by changing vpn-vpn policy in policy
file. Default policy in shorewall is ACCEPT for inter-zone traffic.

-- 
Tuomo Soini <[email protected]>
Foobar Linux services
+358 40 5240030
Foobar Oy <https://foobar.fi/>