Results 1 to 9 of 9

Thread: UFW and VPNs

Hybrid View

  1. #1
    Join Date
    Jul 2005
    Location
    /dev/UK
    Beans
    981
    Distro
    Ubuntu 16.04 Xenial Xerus

    UFW and VPNs

    I've just switched from firestarter to ufw with the gufw gui, and on the whole I'm impressed. However, so far I haven't found a way to allow pptp vpn traffic on the gre protocol p -47, just standard tcp and udp stuff. Anybody have any ideas?

  2. #2
    Join Date
    Jul 2005
    Location
    /dev/UK
    Beans
    981
    Distro
    Ubuntu 16.04 Xenial Xerus

    Re: UFW and VPNs

    OK, after a little reasearch I've found that I need to add iptables commands into the before ufw scripts, although there's suprisingly little documentation about this. The iptables commands I need to add are:

    iptables -I INPUT -p 47 -m state --state ESTABLISHED -j ACCEPT
    iptables -I OUTPUT -p 47 -m state --state NEW,ESTABLISHED -j ACCEPT
    iptables -I INPUT -p tcp --sport 1723 -m state --state ESTABLISHED -j ACCEPT
    iptables -I OUTPUT -p tcp --dport 1723 -m state --state NEW,ESTABLISHED -j ACCEPT

    or even this one:

    # iptables -A INPUT -p 47 -j ACCEPT
    # iptables -A OUTPUT -p 47 -j ACCEPT
    # iptables -A INPUT -p TCP -s 0.0.0.0/0 --source-port 1723 -j ACCEPT
    # iptables -A OUTPUT -p TCP -d 0.0.0.0/0 --destination-port 1723 -j ACCEPT

    I would appreciate it if some ufw guru out there could convert these commands into ufw syntax so that I can use them. Many thanks in advance.
    Last edited by Steve1961; April 5th, 2009 at 04:08 PM.

  3. #3
    Join Date
    Dec 2009
    Beans
    1

    Re: UFW and VPNs

    Thank you for idea, your rules works successfully in such form:

    -A ufw-before-input -p 47 -j ACCEPT
    -A ufw-before-output -p 47 -j ACCEPT
    -A ufw-before-input -p tcp -s 0.0.0.0/0 --sport 1723 -j ACCEPT
    -A ufw-before-output -p tcp -d 0.0.0.0/0 --dport 1723 -j ACCEPT

    (tested on Ubuntu 9.10 with ufw + corbina pptp + network-manager)
    Last edited by Dennis-K; December 26th, 2009 at 05:27 AM.

  4. #4
    Join Date
    Jul 2005
    Location
    /dev/UK
    Beans
    981
    Distro
    Ubuntu 16.04 Xenial Xerus

    Re: UFW and VPNs

    Thanks for the feedback. Actually when onnecting to my work VPN i found that a pptp connection works without any rules - presumably because its stateful

  5. #5
    Join Date
    Oct 2004
    Location
    Arendal, Norway
    Beans
    343

    Re: UFW and VPNs

    Actually putting this
    Code:
    -A ufw-before-input -p 47 -j ACCEPT
    -A ufw-before-output -p 47 -j ACCEPT
    into /etc/ufw/before.rules is enough. TCP port 1723 can be added in the GUI. I'm also seeing some blocking of TCP and UDP port 36224, not sure what that's about.

  6. #6
    Join Date
    Jul 2011
    Beans
    8

    Re: UFW and VPNs

    I have set up PPTP VPN server on ubuntu.
    But accounts are open for concurrent simultaneous connections. means there can be many users using one account at the time.
    i need to limit that to one user at the time.
    anybody knows how it can be done?

  7. #7
    Join Date
    Nov 2009
    Location
    Nutley, NJ
    Beans
    618
    Distro
    Ubuntu 16.04 Xenial Xerus

    Re: UFW and VPNs

    I have an ASUS N61JV-X2 notebook PC with Crucial 8 GB dual-channel 1,066 MHz SODIMM SDRAM and an Intel 2nd Generation 2.5" MLC NAND FLASH X25-M 160 GB Solid State Drive running Ubuntu 12.04 64 bit Long Term Support. I subscribe to WiTopia personal VPN basic for now. I followed the WiTopia guide to setting up PPTP, but it does not work with GUFW. I made an exception rule for outgoing traffic over port 1723 over TCP protocol and I added the rule for IP 47 (GRE) to both iptables and /etc/ufw/before.rules, but I still can not connect via PPTP protocol when GUFW is denying outgoing traffic. I also made an exception rule for ports 80, 443, 8080, and 53 over TCP and UDP protocols respectively.

    How do I get this to work with GUFW?

    I will open up a support ticket with WiTopia soon.

  8. #8
    Join Date
    Feb 2008
    Location
    Texas
    Beans
    22,908
    Distro
    Ubuntu 17.10 Artful Aardvark

    Re: UFW and VPNs

    Thread closed. Please do not post in old threads.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •