On 03/28/2017 08:14 AM, Nemo wrote:
Yes, I did follow the official documentation to create the proxy.

The only thing I've borrowed from the Rudd-O version is having Firewall
downstream from VPN, and setting the VPN's firewall settings to block
all traffic except that on my VPN's port.

Doing updates through the VPN would be perfect if possible.

Adding qubes-updates-proxy service to Firewall-VPN (and installing
tinyproxy via tinyproxy.x86_64) causes an immediate connection error
from dnf. Is that caused by the firewall rules I've added to VPN? Are
they necessary, given a setup via the official documentation?

It depends on where the rules are set, but I think its probable the added rules are blocking updates. This type of setup, with downstream proxyVM handling the updates proxy, is working well for me.

Keep in mind the firewall already has a config to prevent any output not initiated by the VPN client (i.e. OpenVPN, etc) so restricting by port number may not be adding anything to link security.

--

Chris Laprise, [email protected]
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB  4AB3 1DC4 D106 F07F 1886

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/46271c9f-ed60-9267-1ecd-8b41e228fdd1%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to