Re: iptables rules required for OpenVPN and Tor

Peter Davis via Openvpn-users <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <-G05DLME4J6cqo1cUn8T4DCufP74NEl7SAgpyz7MjNTholxG9Jm8wudB6y1JYODSloqkZRQ2YRKl6t7gT-3okw8rMcQRB1wYr8eR3GnMzhw=@proton.me>
>On Friday, January 19th, 2024 at 5:04 PM, Jochen Bern <[email protected]> wrote:


> On 19.01.24 13:59, Peter Davis via Openvpn-users wrote:
> 
> > I want to tunnel OpenVPN on Tor and I found the following iptables rules:
> > 
> > # export OVPN=tun0
> > # IPTABLES -A INPUT -i $OVPN -s 10.8.0.0/24 -m state --state NEW -j ACCEPT
> > # IPTABLES -t nat -A PREROUTING -i $OVPN -p udp --dport 53 -s 10.8.0.0/24 -j DNAT --to-destination 10.8.0.1:53530
> > # IPTABLES -t nat -A PREROUTING -i $OVPN -p tcp -s 10.8.0.0/24 -j DNAT --to-destination 10.8.0.1:9040
> > # IPTABLES -t nat -A PREROUTING -i $OVPN -p udp -s 10.8.0.0/24 -j DNAT --to-destination 10.8.0.1:9040
> 
> 
> Please explain what your definition of "tunnel OpenVPN on Tor" is. These
> rules look rather like running the server's own Tor connection, the
> incoming traffic in particular, through the VPN(s) ("inside" and
> "outside" reversed WRT what your question implies when taken literally),
> and royally hosing any traffic normal VPN clients try to send through
> the server.
> 
> Kind regards,
> --
> Jochen Bern
> Systemingenieur
> 
> Binect GmbH
> _______________________________________________
> Openvpn-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/openvpn-users

Hi,
When someone connects to this server with OpenVPN and uses the Internet, then all his\her Internet connections are tunneled through Tor.
I want to know which group of iptables rules are sufficient!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.