Koozali.org: home of the SME Server

openvpn

Offline trazomtg

  • ***
  • 119
  • +0/-0
openvpn
« on: May 27, 2018, 11:41:44 PM »
hello,
id'like to access to my machines behind my smeserver  from a machine external at my local LAN, anywhere on internet
i am not sure how to parameter this fonction in smeserver

can you help me please because i don't know how to use the doc ?
my smeserver is on 192.168.0.1 connected to my freeboxin gateway/bridge mode with an ethernet connexion and to a switch
my others computers are 192.168.0.3, 192.168.0.7 and 192.168.0.10 are connected to the switch
is it possible from internet (out of my LAN) so anywhere to connect to theses machines?
thanks
T.
« Last Edit: May 27, 2018, 11:45:44 PM by trazomtg »

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: openvpn
« Reply #1 on: May 28, 2018, 01:10:57 AM »
PLEASE read the wiki like we have told you numerous times before. All the information you need is there.

If you have a specific issue then post back here telling us the steps you have taken.

But please stop asking people to walk you by the hand through documented procedures.

If you really do not understand the documentation then tell us which part you specifically do not understand.

If you do not understand any of it you probably should not be attempting this.

Thamk you.
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline trazomtg

  • ***
  • 119
  • +0/-0
Re: openvpn
« Reply #2 on: May 28, 2018, 12:26:14 PM »
ok :-?  i ask because i have not a lot of time

Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: openvpn
« Reply #3 on: May 28, 2018, 12:37:17 PM »
ok, in this case you'd pay someone to do this job for you

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: openvpn
« Reply #4 on: May 28, 2018, 01:14:56 PM »
I charge double while on holiday....
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline DanB35

  • ****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: openvpn
« Reply #5 on: May 28, 2018, 05:18:51 PM »
ok :-?  i ask because i have not a lot of time
...and you obviously couldn't care less about our time.  The thing is, it will take less of your time if you first RTFM, and then ask specific questions if there are specific parts that are unclear.  It will also make us much more willing to help you.

With that said, though the wiki's instructions worked well for me, my ultimate solution was to stop using SME in server/gateway mode, and put it behind a pfSense router.  I then configured the VPN on that device, which worked much more smoothly.
......

Offline Fumetto

  • *
  • 874
  • +1/-0
Re: openvpn
« Reply #6 on: May 28, 2018, 06:38:28 PM »
...my ultimate solution was to stop using SME in server/gateway mode, and put it behind a pfSense router.  I then configured the VPN on that device, which worked much more smoothly.
...or, as I did, put the pfsense in "parallel" to SME and make it become a network gateway, using the LAN side of SME only for the services it has to provide and "saving" to turn doors on SME. Works very well!!! :-)

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: openvpn
« Reply #7 on: May 28, 2018, 07:25:39 PM »
I have a couple in S/G with no issues (but they are on VMs with no interfering routers)

Trickiest bit was hand crafting ovpn configs with embedded certs for iOS. Wish phpki could do it automatically.

Glad I read the wiki and openvpn forums. And gave myself plenty of time :-)
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline janet

  • ****
  • 4,812
  • +0/-0
Re: openvpn
« Reply #8 on: May 29, 2018, 01:21:49 AM »
trazomtg

Your gateway device is NOT an sme server so we cannot give specific advice for VPN'ing into a sme server acting as gateway.
 
You need to read your freeboxin gateway documentation or ask on their forums how to set up a VPN.
« Last Edit: May 30, 2018, 02:28:57 AM by janet »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline DanB35

  • ****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: openvpn
« Reply #9 on: May 29, 2018, 02:58:57 AM »
Your gareway is NOT an sme server so we cannot give advice.
Well, not necessarily--he could forward, say, port 1194 to the SME and go from there.  But not if he doesn't have time to read the documentation, and needs someone to spoon-feed step-by-step instructions...
......

Offline trazomtg

  • ***
  • 119
  • +0/-0
Re: openvpn
« Reply #10 on: May 29, 2018, 03:52:31 PM »
thanks for your replies. Could you give me the url of some documentation please?
it's the most difficult to find

Offline DanB35

  • ****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: openvpn
« Reply #11 on: May 29, 2018, 03:58:53 PM »
Could you give me the url of some documentation please?
it's the most difficult to find
You mean the link that appears at the top of this page ("Documentation"), with a drop-down to "wiki" (which you've been repeatedly told to check) is difficult to find?  For OpenVPN specifically, look at https://wiki.contribs.org/OpenVPN_Routed and https://wiki.contribs.org/OpenVPN_Bridge
......

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: openvpn
« Reply #12 on: May 29, 2018, 04:23:32 PM »
What is really frustrating is the OPs original post here:

https://forums.contribs.org/index.php/topic,53131.msg274865.html#msg274865

Specifically this:

Quote
i am an "old" systems and network international consultant and technical directeur for a very big enterprise. I'm now retired and fave plenty of time.
i have skils in Tivoli, Nagios, MRTG ....
others skills in KVM, OpenVPN, Iptables, linux (Fedora, Debian ), Unix (AIX) ...
and some facilites in bash, python and prolog


Really????? If you have all those skills, why are you finding it so difficult?? Not only with OpenVPN but system monitoring too (see other long 'haven't read the documentation' threads on Nagios et al)

If you were that high up you would know the importance of reading the documentation?

And if you are retired you have a lot more time than the rest of us who are working.

Sorry, but something is not right here and I don't have time to waste on users who have more time than me, and cannot be bothered to do some homework.

...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline TerryF

  • grumpy old man
  • *
  • 1,826
  • +6/-0
Re: openvpn
« Reply #13 on: May 30, 2018, 02:18:41 AM »
There are times you need to have a "Like" button :-)
--
qui scribit bis legit

Offline trazomtg

  • ***
  • 119
  • +0/-0
Re: openvpn
« Reply #14 on: June 08, 2018, 11:56:24 AM »
Fumetto  and  DanB35,  i don't understand your replies


With that said, though the wiki's instructions worked well for me, my ultimate solution was to stop using SME in server/gateway mode, and put it behind a pfSense router.  I then configured the VPN on that device, which worked much more smoothly.
...or, as I did, put the pfsense in "parallel" to SME and make it become a network gateway, using the LAN side of SME only for the services it has to provide and "saving" to turn doors on SME. Works very well!!!

trazomtg

Your gateway device is NOT an sme server so we cannot give specific advice for VPN'ing into a sme server acting as gateway.
 
You need to read your freeboxin gateway documentation or ask on their forums how to set up a VPN.

Well, not necessarily--he could forward, say, port 1194 to the SME and go from there.  But not if he doesn't have time to read the documentation, and needs someone to spoon-feed step-by-step instructions...

can you explain this solution or give me a doc?  i don't find doc in SMEServer doc

all my traffic from internet throughs the freebox and goes to the SMESERVER then the switch then the computers
« Last Edit: June 08, 2018, 12:00:08 PM by trazomtg »