Search found 15 matches

by pearsimmon
Mon Jul 08, 2019 12:41 pm
Forum: Software / Configuration
Topic: Custom OpenVPN killswitch problem
Replies: 4
Views: 2222

Re: Custom OpenVPN killswitch problem

Sorry to bump this, but I found a solution for the gid-owner approach.
It turns out 'iptables' checks only if a given group is user's primary, but won't work if a user merely belongs (branches out) to this group. So since 'openvpn' must be run with 'sudo', I had to change root's primary group to ...
by pearsimmon
Fri Jul 05, 2019 6:11 am
Forum: Software / Configuration
Topic: Custom OpenVPN killswitch problem
Replies: 4
Views: 2222

Re: Custom OpenVPN killswitch problem


the issue in first approach is almost definitely in this line:
sudo iptables -A OUTPUT -j ACCEPT -m owner --gid-owner openvpn
Relevant: https://unix.stackexchange.com/a/413835

So it seems it's a bug in iptables's extension. Does someone have an idea how to apply this solution in most clean ...
by pearsimmon
Thu Jul 04, 2019 3:09 pm
Forum: Software / Configuration
Topic: Custom OpenVPN killswitch problem
Replies: 4
Views: 2222

Re: Custom OpenVPN killswitch problem

That did it, the "ufw" approach now works correctly. But I wonder why the first approach doesn't work? It looked very promising because it does not require manually resolving and then hardcoding IP addresses for each config file.

---edit:

After some insight, the issue in first approach is almost ...
by pearsimmon
Thu Jul 04, 2019 11:18 am
Forum: Software / Configuration
Topic: Custom OpenVPN killswitch problem
Replies: 4
Views: 2222

Custom OpenVPN killswitch problem

I'm having trouble setting up a killswitch for a given OpenVPN config file. Basically, I want all connections outside of VPN to be dropped, except loopback and local subnet.

I was experimenting with this free OpenVPN config: https://www.freeopenvpn.org/en/cf/russia.php
By itself, without further ...
by pearsimmon
Mon Jun 03, 2019 3:58 am
Forum: Software / Configuration
Topic: OpenVPN killswitch
Replies: 3
Views: 1264

Re: OpenVPN killswitch

Well, I was hoping it is incorporated in network manager's GUI somewhere but if not, I will use iptables or ufw. The problem is that if I want to disable VPN sometimes to access my bank account for example, I will have to revert iptables or ufw manually.
by pearsimmon
Sun Jun 02, 2019 5:07 pm
Forum: Software / Configuration
Topic: OpenVPN killswitch
Replies: 3
Views: 1264

OpenVPN killswitch

I can easily import an .ovpn file with the GUI network manager, but I'd also like to have a working killswitch, so that if VPN connection drops, I lose access to the Internet instead of reverting to my bare connection. I checked "advanced" options but I'm not that knowledgeable to understand ...
by pearsimmon
Sun May 12, 2019 4:48 pm
Forum: Package Requests / Status
Topic: REQUEST: balenaEtcher
Replies: 31
Views: 12851

Re: REQUEST: balenaEtcher

But can MX Live USB Maker create from any iso, including Windows?
by pearsimmon
Sun May 12, 2019 5:54 am
Forum: Package Requests / Status
Topic: REQUEST: balenaEtcher
Replies: 31
Views: 12851

Re: REQUEST: balenaEtcher

Hmm, for me it works fine.
Actually it would be nice if there was an integrated bootable stick maker in Thunar's custom actions. I miss this feature, coming from Linux Mint.
by pearsimmon
Sat May 11, 2019 2:49 pm
Forum: Package Requests / Status
Topic: REQUEST: balenaEtcher
Replies: 31
Views: 12851

REQUEST: balenaEtcher

balenaEtcher is an open-source tool for creating bootable pendrives.
https://www.balena.io/etcher/

They have an official .deb repo, both x86 and x64, with instructions how to add it here: https://github.com/balena-io/etcher#debian-and-ubuntu-based-package-repository-gnulinux-x86x64
Such version ...
by pearsimmon
Sun May 05, 2019 9:00 am
Forum: Package Requests / Status
Topic: REQUEST: Python packages frontend in MX Package Installer
Replies: 4
Views: 1771

Re: REQUEST: Python packages frontend in MX Package Installer

Thanks for your input, I will remove the custom secure path entry then.

Go to advanced search