@fedora

Страница 764 из 2988
Tobias?
02.06.2017
16:12:52
Speaking of music, my coworker shared Miracle of Sound's album and i had no idea - dang XD

dun like code
You have the pleasure of running t on your computer tough.

pedro
02.06.2017
16:13:07
https://www.youtube.com/watch?v=Ow_OjkSLZDI

Tobias?
02.06.2017
16:13:16
it doesnt matter if you write it or use it :P

Google
pedro
02.06.2017
16:13:16
for those into world music

or havce good taste

ahjaha

sorry bout typos

Tobias?
02.06.2017
16:15:33
Eduard
02.06.2017
16:15:41
I use that, because I need to setup a VPN connection and it fails because of the firewalld

I'm a client to that connection

Tobias?
02.06.2017
16:15:55
And ideally, deploy OPNsense wherever you want to connect to and set "P2P" Mode

Eduard
02.06.2017
16:15:55
Not a server

So I can't set anything

Tobias?
02.06.2017
16:16:16
I'm a client to that connection
Again, Openvpn does clients

Eduard
02.06.2017
16:16:30
I just use new VPN with the NM widget

Google
Tobias?
02.06.2017
16:16:54
I have it both ways - my home firewall acts as client for a p2p connection to my server for example so i can access the internal network from my home

the client doesnt need to have anything set but where to connect to.

Openvpn will do the heavy lifting work of connecting, configuring routes, making sure the client doesnt need to open a port to connect and all.

Eduard
02.06.2017
16:18:30
Ok, let me see. I just do: Network->New (throught "+" button)->VPN->PPTP

Tobias?
02.06.2017
16:18:53
I do Network > New > Import from File

After generating or getting a .ovpn from a server anywhere

pedro
02.06.2017
16:19:25
Tobias?
02.06.2017
16:19:27
(you need to adjust the port if you set a different one)

Eduard
02.06.2017
16:19:34
I don't have access to the server

pedro
02.06.2017
16:19:38
then where do u enter your credentials?

Tobias?
02.06.2017
16:19:57
I don't have access to the server
Tell the server owner to open ovpn then - he has to offer pptp vpn after all too.

and openvpn beats the living hell out of pptp

then where do u enter your credentials?
In the main window after it imported?

pedro
02.06.2017
16:20:26
kay

ill check it later

Eduard
02.06.2017
16:20:43
Mmmm... That will not happen... At least no in my organization

Tobias?
02.06.2017
16:20:52
I moved mine to use it instead and we are working to move a customer onto it too

Eduard
02.06.2017
16:21:16
Because network managers are stupids and don't care about nobody else in the company

Google
Tobias?
02.06.2017
16:21:58
Because network managers are stupids and don't care about nobody else in the company
They care about their job - and openvpn takes a ton of configuration away that needs to be done manually. It'd be easier for them.

(■_■¬)
02.06.2017
16:23:00
Because network managers are stupids and don't care about nobody else in the company
I have been there. Who in the @#$% world disable 6666 and 6667 port or ssh in a Library Wifi?

Tobias?
02.06.2017
16:23:09
Unless they have the "Make yourself not replaceable" Syndrome

(■_■¬)
02.06.2017
16:23:47
LOL!
I use ssh for git...

Tobias?
02.06.2017
16:23:56
https://www.speedguide.net/port.php?port=6666

And that is why i always have an emergency vpn on 80/tcp

Eduard
02.06.2017
16:24:33
Unless they have the "Make yourself not replaceable" Syndrome
Nah, they are just lazy enough to don't do aboslutely nothing. They create all VPNs with a script where they just put the IP of the gateway

Tobias?
02.06.2017
16:24:37
Almost nobody blocks _that_

(■_■¬)
02.06.2017
16:24:53
Because there are "fraudulent" entries for 6666.
I didn't know this. I ended up using a web client for IRC.

Eduard
02.06.2017
16:25:24
Yes

And they don't care

Because our "remote work" VPN

From the start node we connect to a proper IPSec Network, that is real secure

Tobias?
02.06.2017
16:26:35
IPSec ?

Eduard
02.06.2017
16:26:40
So, if this VPN falls or is attacked, they answer is: goes to the site and connect directly

IPSec ?
They use openswan, it's not that bad

Tobias?
02.06.2017
16:27:06
Google
Tobias?
02.06.2017
16:27:28
They use openswan, it's not that bad
I dont get the whole ipsec thing after being bathed in glory by openvpn

天荣
02.06.2017
16:27:33
I have been there. Who in the @#$% world disable 6666 and 6667 port or ssh in a Library Wifi?
In my library nothing is allowed apart from 80/HTTP and 443/TLS.

For example: You can't use 443/SSH

Tobias?
02.06.2017
16:27:46
literally every other vpn, especially commercial, suddenly looks really much "Fuck that"

norj
02.06.2017
16:28:12
For example: You can't use 443/SSH
Can you get around that?

Tobias?
02.06.2017
16:28:21
天荣
02.06.2017
16:28:22
Can you get around that?
Hahahahaha. Of course, of course.

(■_■¬)
02.06.2017
16:28:22
Admin
ERROR: S client not available

天荣
02.06.2017
16:28:26
Everything can be bypassed.

VPN on 80/tcp
Not HTTP. Won't work on DPI.

But what works is stunnel + OpenVPN over 443

Tobias?
02.06.2017
16:28:43
It hurts.
That is their default catchall setting to allow as little as possible

天荣
02.06.2017
16:28:53
Stupid DPI firewalls see the packets as TLS and assume it's HTTPS

Tobias?
02.06.2017
16:29:12
Stupid DPI firewalls see the packets as TLS and assume it's HTTPS
Dude even on DPI active most of the time http passes trough

Their "DPI" is checking the host header for where to

天荣
02.06.2017
16:29:29
What do you mean?

Tobias?
02.06.2017
16:29:34
and if its a known free vpn block it

Google
norj
02.06.2017
16:29:51
So need a vpn to get around this.

Tobias?
02.06.2017
16:29:51
since i use 10 different domains to access the same server...

XD

(■_■¬)
02.06.2017
16:29:57
Tobias?
02.06.2017
16:30:09
So need a vpn to get around this.
yep. a private one - most dont offer those ports.

Eduard
02.06.2017
16:30:16
DPI is kind of my area

:D

Tobias?
02.06.2017
16:30:26
What they use as DPI?
commercial filter shit

Something that has some kind of ISO Cert or something

Eduard
02.06.2017
16:30:41
Not all commercial are shit

Sandvine is pretty good

Tobias?
02.06.2017
16:30:55
They dont care if it works, it just needs to pass ISO or something

Eduard
02.06.2017
16:30:56
And they work on BSD

Tobias?
02.06.2017
16:31:03
Sandvine is pretty good
We dont want it to be good.

(■_■¬)
02.06.2017
16:31:04
Tobias?
02.06.2017
16:31:12
If its good it might block our vpns.

XD

Eduard
02.06.2017
16:31:20
And contribute with the FreeBSD

:s/chit/shit/
Corrected ;)

You are in grammar ninja mode today, no?

Страница 764 из 2988