NethServer Version: NethServer release 7.3.1611 (Final) Module: OpenVPN vs Shorewall
Hi;
When I connect over OpenVPN
my client loose the connection with the outside world
into the nethserver I found this; like Shorewall block my http queries
I also have similar message if I try to ping from my client.
Mar 2 23:45:29 maat kernel: Shorewall:ovpn2net:REJECT:IN=tunrw OUT=eth0 MAC= SRC=10.10.10.6 DST=95.100.49.183 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=29313 DF PROTO=TCP SPT=35298 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0
Ironically DNS still able to resolv.
ping www.com
PING www.com (69.172.201.208) 56(84) bytes of data.
ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
From 10.10.10.1 icmp_seq=1 Destination Host Unreachable
ping 10.10.10.1
PING 10.10.10.1 (10.10.10.1) 56(84) bytes of data.
64 bytes from 10.10.10.1: icmp_seq=1 ttl=64 time=8.40 ms
64 bytes from 10.10.10.1: icmp_seq=2 ttl=64 time=8.55 ms
64 bytes from 10.10.10.1: icmp_seq=3 ttl=64 time=8.61 ms
####Others points might help to understand what iām missing
the firewall rules was made by the installer
ļ green,red ļ ø ļ firewall ļ openvpn@host-to-net
OpenVPN is Routed mode
Nethserver have a unique and only possible interface and is directly connected to the Internet
#####to be clear
laptop client ā the INTERNET ā Nethserver
Iām not on the same network and neither in the same physical place.
I just recently posted exactly the same issue here: VPN no route to internet I will gladly join your search for a solution here.
1 green nic, vpn works, cant get out of the NS.
@filippo_carletti suggested to check āsystemctl status shorewallā
Looks nominal. @JOduMonT could you check that on your end, too?
The last days I could not ping google. Today all of a sudden without any changes that seems to work. Still can not load any websites. Maybe DNS is not working?
Excuse me, I am obviously incompetent. When I am logged into the NS via ssh as root, of cource I can ping everything. From my ouside PC I still can not. No router, no Google, only the nethserver at home.
I am not using squid and there are no such log files listed in the server manager.
Iām sorry, but I canāt figure out your problem.
I connect via openvpn in the evening when Iām at home, I never had problems.
Could you please sen me the output of config show openvpn@host-to-net so that I can reproduce your setup?
Thank you.
Steps 6-8 were not necessary, you should have had it working after shorewall restart without disconnecting.
Now Iām completely lost. Could you please post /etc/shorewall/policy?