Skip to content
This repository has been archived by the owner on Feb 12, 2024. It is now read-only.

IPTables NAT not good for SiteToSite VPN #9

Open
Rolf-M opened this issue Apr 7, 2022 · 1 comment
Open

IPTables NAT not good for SiteToSite VPN #9

Rolf-M opened this issue Apr 7, 2022 · 1 comment

Comments

@Rolf-M
Copy link

Rolf-M commented Apr 7, 2022

This is not really a fault of the script, but anyways:
The implementation of the IP-Tables Masquerading rules in the up/down script is not really helpful.
If you are planing to build a S2S scenario, you usually have an idea about what and how you route. If you are going to masquerade everything behind the tunnel-IP, then you may potentially break firewall rules on the other end of the tunnel!
Moreover you are not adding the rules to the "UBIOS_POSTROUTING_USER_HOOK", which is the default table on the UDM, but to the normal Postrouting table. This works, but was hard for me to find.
Took me a day to find out why my VOIP Phones had no Audio behind the tunnel, until I saw those lines within the script. Commented them out and now I'm happy...

@cpriest
Copy link
Owner

cpriest commented Apr 8, 2022

Sorry, this was just something I was able to hack together for my needs. If you have any changes to contribute back via a PR I'd be happy to integrate them.

I know enough about networking to be dangerous, not an expert though.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants