UDP problem…



I found a peculiar problem while I was setting up an openvpn link the other day. The goal was a simple shared key setup and I started with the sample configuration and modified it a bit to fit the circumstances, I allowed the correct UDP port through the firewall (I think 1194 if I recall correctly) and … it didn’t work. So…. I started over and worked from empty config files and put in the bare minimums… it still didn’t work – no appearance that it was making the connection at all to negotiate the link. I double and triple checked the firewall config/restarted it… nothing Then I decided to try TCP instead of a UDP port. Changed the firewall config to allow the TCP traffic on 1194, adjusted the server and client config and lo and behold it worked. The firewall in question….


Is a VERY old and due for software rebuild Mandrake SNF (Single Network Firewall). I had hoped to be able to go the upgrade route to the MNF series, but license changes there have made the price for them out of reason. (And if I were to do it, I’d have to make too many modifications to make it worth doing). Of course, MNF2 isn’t freely available at all (as per my last check.) So… IPcop may be in the future for that setup.

The bottom line is that there seems to be something funky with UDP and this Mandrake SNF install. The moral of the story may be to consider TCP if you run into problems with a UDP connection over a firewall (and can choose the protocol.)

Related Posts

Blog Traffic Exchange Related Posts
  • Ultravnc for remote computer support A little while back I talked some about TightVNC which for a long time has been my favorite implementation of a remote framebuffer, or remote desktop viewing protocol known as VNC (Virtual Network Computing.) The original VNC (now realvnc) came out of AT&T research labs in the UK and has......
  • IPtables magic, or... Blocking Aggressive Outbound Traffic with IPtables Blocking Aggressive Outbound Traffic with IPtables. For starters, I've tested this on a test system that started out with NO iptables rules, and then moved on to an IPCop install (the vmware download from vmwarez.com...) I've detailed previously one dilemma that I had with regard to my own cable connection......
  • What a week.... I think it's time to pass along a long story of what's gone on over the last week or so here and some of the reasons there hasn't been anything posted. Generally, I would say that work has been busy, but something happened last week that went a bit beyond......
Blog Traffic Exchange Related Websites
  • 3 More Diet Pills That Didn't Work For Me I started off in my post "3 Diet Pills That Didn't Work For Me" describing some of the less-than-optimal experiences I have had with various diet pills. Jumping right into the second half of my list: 1. Hoodia General Info: Hoodia is supposed to be an appetite suppressant. On most......
  • Working after Receiving Social Security at Age 62 There are sound financial reasons for waiting to your full retirement age to claim Social Security retirement benefits. ┬áDelaying Social Security until age 70 can enhance those benefits even more. ┬áNevertheless, many baby boomers will determine that they must or should begin receiving benefits at age 62. Unfortunately, many retirees......
  • Swom Review: First Let's Start With The Bad Stuff Swom Review: I have been a gold member of Swom For about 2 months now. So I feel this is a good time to share with you what my opinion of this site is. First let's start with the bad stuff Swom is a very basic social network , you......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site