-
spacekitty420[m]
henlo, does anyone knows if there's a way for iVPN not to override firewall rules from ufw?
-
spacekitty420[m]
llike, on mullvad i have to manually allow outgoing to the vpn's ip cause denying by default outgoings
-
spacekitty420[m]
but ivpn it just dont give no fuck, even if all locked up with deny incoming and deny outgoing it's still connects to the vpn's server by overriding ufw's rules with its own firewall or somethin somethin.... :hyperthonk:
-
spacekitty420[m]
like, even if turning ivpn's firewall off (tried both on cli and ui), it still dont give no fuck about ufw and just doing its thing nonetheless
-
ZombieMaster[m]
> <@spacekitty420:matrix.org> henlo, does anyone knows if there's a way for iVPN not to override firewall rules from ufw?... (full message at
libera.ems.host/_matrix/media/r0/do…56b93fb09aa3d27dd707a22a799459befd2)
-
ZombieMaster[m]
don't know about ufw but using iptables can be a pita to route correctly
-
ZombieMaster[m]
mostly NAT settings though
-
spacekitty420[m]
> <@zombie_master:halogen.city> there is a switch on ivpn to disallow connecting to (rest of the) internet if not connected to vpn.... (full message at
libera.ems.host/_matrix/media/r0/do…96f7198431ab68bc50b6f1fa2192868c146)
-
ZombieMaster[m]
you have to nat br0 or whatever through tun0 (created by ivpn)
-
spacekitty420[m]
br0 is on host, tun0 on the vm, i dont think it work like that and i wouldnt know how to either 😿
-
ZombieMaster[m]
oh
-
ZombieMaster[m]
so you connect to vpn from inside vm
-
spacekitty420[m]
yeah
-
ZombieMaster[m]
that is different
-
ZombieMaster[m]
i thought you connected with host to vpn
-
ZombieMaster[m]
hmmm
-
spacekitty420[m]
right, been trying that setup on an other rig too and share the vpn's connection to the vm and indeed would have had to nat tun0 to br0, been googling that alot and just couldnt find how
-
spacekitty420[m]
rn is something else tho yeah :P
-
ZombieMaster[m]
you can check out the routes with `route`
-
ZombieMaster[m]
i think ivpn handles a set of iptables rules
-
ZombieMaster[m]
that may mess with ufw
-
ZombieMaster[m]
do you have iptables installed?
-
ZombieMaster[m]
you can print the rules for chains to check out
-
ZombieMaster[m]
if something is not routed/nated properly
-
spacekitty420[m]
iptables soooo much of a headache tho LOL, is why am using ufw cause i hate iptables
-
spacekitty420[m]
it's installed yeah, would have to do some googling again for the commands but iirc when adding rules to ufw then it also shows up on iptable
-
spacekitty420[m]
so guessing you might be right, ivpn might be doing through iptables as well, hence overwritting ufw
-
spacekitty420[m]
thank you for your insights, ill be checking on iptables when i not lazy, most likely will be able to figure something from there :3
-
ZombieMaster[m]
feel free to DM at any time to further discuss such problems :)
-
spacekitty420[m]
alrighty, thank you alot <3
-
spacekitty420[m]
-
spacekitty420[m]
s///
-
spacekitty420[m]
-
spacekitty420[m]
nvm nvm got it working \o/, by setting the vpn to launch on boot (with its integrated firewall disabled) after having down the iptables command to delete the rules allowing outgoing to any
-
spacekitty420[m]
pog :3
-
spacekitty420[m]
s/down/done/
-
sethforprivacy
Pretty solid VICE Motherboard article on privacy in cryptocurrencies, including a solid focus on Monero, went live today:
vice.com/en/article/v7dqk8/what-hap…the-dream-of-private-cryptocurrency
-
sethforprivacy
Overall, much better than expected!
-
unsanctioned
-
sethforprivacy
Yeah, much more well-informed than most and much less anti-privacy. Always get worried when MSM wants to cover Monero, but this was pretty damn solid.
-
sethforprivacy
I tried to make that very clear in my comments, and obviously they understand the difference as well -- really, really impressed.
-
entry1[m]
Great and non-maximalist appeal to use Monero. Nearly no mention of price which was wonderful as it will show the merit of the project past the price boasting/discussion. More demand will always equate to a higher price down the road, but love to see more organic growth/speculation.