Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Steve Coleman

On 08/14/18 16:43, Who Cares wrote:

I´m trying to implement this Kerio-control system.
I thought this would have been a nice combo of firewall and VPN.



You might want to read up on the Qubes Proxy VPN setup and compare how 
that works with what KerioControl is expecting for its environment. That 
way your client VM's can choose to connect to the proxy and possibly use 
the VPN by default. The Whonix system would be a good example for this.


How To make a VPN Gateway in Qubes
https://www.qubes-os.org/doc/vpn/

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9664267f-f672-de6a-229f-0ac1ac657d00%40jhuapl.edu.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Who Cares
I´m trying to implement this Kerio-control system.
I thought this would have been a nice combo of firewall and VPN.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9ebefede-32d0-4a88-b9ec-90fc49fdabf2%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Chris Laprise

On 08/14/2018 02:22 PM, Steve Coleman wrote:

On 08/14/18 13:40, Who Cares wrote:


I am using qubes 4.0 and i am trying to install a firewall.


Qubes comes with an integrated firewall in the sys-firewall VM. It uses 
managed iptables which provide the basic rules to protect the system, 
but also allow you to make adjustments as required for your unique 
situation.


So, I'm not sure why you think you need to add yet another firewall

The architecture is generally

YourVM -> sys-firewall -> sys-net -> LAN Network

You get this setup right out of the box, with no configuration required.

Perhaps you could explain better what you are trying to accomplish?



I hope anyone would spend some time helping me with this project of mine.

At the end it is one PC where is installed qubes. This one is a 
local-server

This PC got 2 LAN devices i could attach separately.
I want 2 routes.

Route 1: Net-VM(LAN 1) --> firewall-VM(Kerio-Control with VPN)
Route 2: Windows-Server HVM with a specific Programm.(attached LAN 2)

Scenario 1: Local Network Windows PC working with a Programm wich need 
this Windows Server Programm Service


Scenario 2: A dude located in Timbuktu(or whatever) want to work on 
the same local Network using the kerio-control VPN and his Windows 
device needs to communicate with the windows Server.


Any thougts about this ?


If you can find out which VPN protocol this kerio-control is using, then 
you may be able to do this better with native Qubes tools.


Their VPN protocol appears to be IPsec (which isn't great BTW); you 
could start with a Linux IPsec tutorial in a proxyVM to see if you can 
connect to this other person.


--

Chris Laprise, tas...@posteo.net
https://github.com/tasket
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB  4AB3 1DC4 D106 F07F 1886

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b06c427a-1775-4f7d-c147-8220bd755254%40posteo.net.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Steve Coleman

On 08/14/18 13:40, Who Cares wrote:


I am using qubes 4.0 and i am trying to install a firewall.


Qubes comes with an integrated firewall in the sys-firewall VM. It uses 
managed iptables which provide the basic rules to protect the system, 
but also allow you to make adjustments as required for your unique 
situation.


So, I'm not sure why you think you need to add yet another firewall

The architecture is generally

YourVM -> sys-firewall -> sys-net -> LAN Network

You get this setup right out of the box, with no configuration required.

Perhaps you could explain better what you are trying to accomplish?



I hope anyone would spend some time helping me with this project of mine.

At the end it is one PC where is installed qubes. This one is a local-server
This PC got 2 LAN devices i could attach separately.
I want 2 routes.

Route 1: Net-VM(LAN 1) --> firewall-VM(Kerio-Control with VPN)
Route 2: Windows-Server HVM with a specific Programm.(attached LAN 2)

Scenario 1: Local Network Windows PC working with a Programm wich need this 
Windows Server Programm Service

Scenario 2: A dude located in Timbuktu(or whatever) want to work on the same 
local Network using the kerio-control VPN and his Windows device needs to 
communicate with the windows Server.

Any thougts about this ?


Thanks so far!



--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/f8711937-6817-f9ea-9ebe-09428a7d19e9%40jhuapl.edu.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Who Cares
Hello,

I am using qubes 4.0 and i am trying to install a firewall.
I try to isntall kerio control (http://www.kerio.de/products/kerio-control) as 
it supports VPN. At the end i want to use it as the firewall-VM rather than buy 
a physical firewall.

Kerio-control got some several versions:

  1: software Applience (linux kernel 3.16 based OS)
  2: VMware Virtual Applience
  3: Hyper-V Virtual Applience

I thought it would be possible first to install the it using the software 
applience in a HVM. So I made a HVM with no kernel and started it assigning the 
installation ISO like this :

qvm-start kerio --cdrom=:/home/user/Downloads/kerio.iso

It is booting it in the VM, but installation fails at the point where it says " 
no supported drive found ".
Then I searched if it would be possible attaching a specific drive-device just 
for this VM in the Quebes Manager. And this it so far. I am stuck here now.

I dont know how i could install it so I can use it as Firewall and the 
VPN-features.

Did I use the wrong Applience ?
Or can I imitate a physical Drive only for this VM ?

I hope anyone would spend some time helping me with this project of mine.

At the end it is one PC where is installed qubes. This one is a local-server
This PC got 2 LAN devices i could attach separately.
I want 2 routes.

Route 1: Net-VM(LAN 1) --> firewall-VM(Kerio-Control with VPN)
Route 2: Windows-Server HVM with a specific Programm.(attached LAN 2)

Scenario 1: Local Network Windows PC working with a Programm wich need this 
Windows Server Programm Service

Scenario 2: A dude located in Timbuktu(or whatever) want to work on the same 
local Network using the kerio-control VPN and his Windows device needs to 
communicate with the windows Server.

Any thougts about this ?


Thanks so far! 

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/f8b8d2d0-3a26-4d49-b260-0c18b19b1a66%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.