On 03/28/2017 08:14 AM, Nemo wrote:
Yes, I did follow the official documentation to create the proxy.
The only thing I've borrowed from the Rudd-O version is having Firewall
downstream from VPN, and setting the VPN's firewall settings to block
all traffic except that on my VPN's port.
Doing updates through the VPN would be perfect if possible.
Adding qubes-updates-proxy service to Firewall-VPN (and installing
tinyproxy via tinyproxy.x86_64) causes an immediate connection error
from dnf. Is that caused by the firewall rules I've added to VPN? Are
they necessary, given a setup via the official documentation?
It depends on where the rules are set, but I think its probable the
added rules are blocking updates. This type of setup, with downstream
proxyVM handling the updates proxy, is working well for me.
Keep in mind the firewall already has a config to prevent any output not
initiated by the VPN client (i.e. OpenVPN, etc) so restricting by port
number may not be adding anything to link security.
--
Chris Laprise, [email protected]
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886
--
You received this message because you are subscribed to the Google Groups
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/qubes-users/46271c9f-ed60-9267-1ecd-8b41e228fdd1%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.