UDP problem…



I found a peculiar problem while I was setting up an openvpn link the other day. The goal was a simple shared key setup and I started with the sample configuration and modified it a bit to fit the circumstances, I allowed the correct UDP port through the firewall (I think 1194 if I recall correctly) and … it didn’t work. So…. I started over and worked from empty config files and put in the bare minimums… it still didn’t work – no appearance that it was making the connection at all to negotiate the link. I double and triple checked the firewall config/restarted it… nothing Then I decided to try TCP instead of a UDP port. Changed the firewall config to allow the TCP traffic on 1194, adjusted the server and client config and lo and behold it worked. The firewall in question….


Is a VERY old and due for software rebuild Mandrake SNF (Single Network Firewall). I had hoped to be able to go the upgrade route to the MNF series, but license changes there have made the price for them out of reason. (And if I were to do it, I’d have to make too many modifications to make it worth doing). Of course, MNF2 isn’t freely available at all (as per my last check.) So… IPcop may be in the future for that setup.

The bottom line is that there seems to be something funky with UDP and this Mandrake SNF install. The moral of the story may be to consider TCP if you run into problems with a UDP connection over a firewall (and can choose the protocol.)

Related Posts

Blog Traffic Exchange Related Posts
  • The great firewall of China The great firewall of China may be just an illusion in technical terms. This article describes the details of how things work.... Basically when "banned content" is detected, both ends of the connection are sent a flood of tcp reset packets. Which (if both sides are designed to pay attention......
  • IPtables magic, or... Blocking Aggressive Outbound Traffic with IPtables Blocking Aggressive Outbound Traffic with IPtables. For starters, I've tested this on a test system that started out with NO iptables rules, and then moved on to an IPCop install (the vmware download from vmwarez.com...) I've detailed previously one dilemma that I had with regard to my own cable connection......
  • What a week.... I think it's time to pass along a long story of what's gone on over the last week or so here and some of the reasons there hasn't been anything posted. Generally, I would say that work has been busy, but something happened last week that went a bit beyond......
Blog Traffic Exchange Related Websites
  • 3 More Diet Pills That Didn't Work For Me I started off in my post "3 Diet Pills That Didn't Work For Me" describing some of the less-than-optimal experiences I have had with various diet pills. Jumping right into the second half of my list: 1. Hoodia General Info: Hoodia is supposed to be an appetite suppressant. On most......
  • I Just Found Something To Make Your Network Marketing Better Image by websuccessdiva via Flickr I found something that actually is very cool, matter of fact I learned so much so fast that in two days the information I received changed the way I blog online. This is something you can use even if you are not interested in......
  • Network Marketing Blog - It's Time To Take It Up A Notch! Network Marketing Blog - Why Blogging Is Stupid Easy   [/caption] On a regular basis I see sites that are starting to tell people how important blogging is to their business.  I made a huge mistake when I first started telling people they should blog back in 2006. That mistake......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site