LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-15-2009, 11:11 PM   #1
jonnytabpni
Member
 
Registered: Sep 2008
Posts: 68

Rep: Reputation: 16
OpenVPN IP Spoofing


Hi Folks,

Just about to set up an openvpn system for member of the public. I'm using a routed (dev tun) openvpn system.

Now my questions is:

I know that I can push certain IP's to clients. Now, on a normal LAN, clients are free to change their IP address manually (Just by going into network settings). Can this be done in Openvpn? Hopefully not

I tried this on a test bed and it didn't work (which is great!) - the server just kept saying "bad source address" or something like that.

So does openvpn really prevent IP spoofing? Or was I not doing something to make my spoof attack work?

Cheers

P.S. The reason why IP is so important is that my squid logging system is based on client IP connections
 
Old 04-17-2009, 12:39 AM   #2
rossonieri#1
Member
 
Registered: Jun 2007
Posts: 359

Rep: Reputation: 34
hi,

nice idea,
never tried that - but, i'm wondering which IP/subnet did you push to the VPN client?
was it something like /32, or /30 as p2p links or a standard subnet like /24 etc?

my catch is that you can not change an IP being used in an established VPN session just like that - unlike on basic ethernet network.

just a thought.

anyway, i see that you need a squid mechanism to disconnect an overlimit session in your tunnel server? on the other post.

yes, you can do that - try to search around squid delay pool.
i've seen my friends doing that to limit and even to drop downloads if it has reaching the limit (aside from using ACLs).
yes, the basic squid delay pool purpose was only to limit/shaping the link - but, with a little hack - it can drop the connection too.

HTH.

Last edited by rossonieri#1; 04-17-2009 at 12:41 AM.
 
Old 04-17-2009, 12:23 PM   #3
TimothyEBaldwin
Member
 
Registered: Mar 2009
Posts: 249

Rep: Reputation: 27
If you use tun mode IP spoofing is prevented, in tap mode it behaves like Ethernet.
 
Old 04-18-2009, 03:21 AM   #4
jonnytabpni
Member
 
Registered: Sep 2008
Posts: 68

Original Poster
Rep: Reputation: 16
That's great about openvpn ip spoofing! One stept closer to my needs!

You were mentioning Squid delay pools - is there any way to log the amount used though and somehow dynamically change them if e.g. the client were to "top his account up"?
 
Old 04-18-2009, 10:44 AM   #5
rossonieri#1
Member
 
Registered: Jun 2007
Posts: 359

Rep: Reputation: 34
hi,

you mean squid logging? or perhaps any other logging?
squid logging basically can be done using squid analyzer via webmin module.

http://freshmeat.net/projects/squidanalyzer/

but the drop if over limit mechanism should be done via delay pool. if you can write some script - i think you can combine them both.

and you can also put an openldap-based browser authentication - so that you dont have to open the whole VPN port - just what your users need to have like 80, 443, 53 etc.

HTH.

Last edited by rossonieri#1; 04-18-2009 at 10:46 AM.
 
Old 04-19-2009, 01:28 PM   #6
jonnytabpni
Member
 
Registered: Sep 2008
Posts: 68

Original Poster
Rep: Reputation: 16
Hi rossonieri,

Where did you find a plugin for Sqyiud Analyzer? It sounds pretty good from that link you gave me

Cheers
 
Old 04-19-2009, 10:59 PM   #7
rossonieri#1
Member
 
Registered: Jun 2007
Posts: 359

Rep: Reputation: 34
hi jonny,

you may also check SARG - Squid Analyzer and Report Generator :
http://sarg.sourceforge.net/

or as a webmin module :
http://www.webmin.com/cgi-bin/search....cgi?modules=1

(just Ctrl+F and type "squid")

HTH.
 
  


Reply

Tags
openvpn



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenVPN client has not default gateway when connect to OpenVPN server sailershen Linux - Security 3 03-04-2010 02:20 AM
IP spoofing tekmann33 Linux - Newbie 2 01-08-2009 11:03 AM
OpenVPN Question : connecting 5-6 comps with OpenVPN duryodhan Linux - Networking 7 02-15-2007 10:28 PM
IP spoofing prinski Linux - Security 2 03-25-2004 12:27 PM
Ip spoofing !! freelinuxcpp Linux - Networking 4 03-01-2004 01:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration