Re: [Openvpn-users] Success story (and some small complaints about the HOWTO)

  • Subject: Re: [Openvpn-users] Success story (and some small complaints about the HOWTO)
  • From: Johannes Schindelin <Johannes.Schindelin@xxxxxx>
  • Date: Sat, 21 Jul 2007 22:48:29 +0100 (BST)


On Sat, 21 Jul 2007, Les Mikesell wrote:

> I'd consider the most likely approach to be to find the person that 
> configures the firewall and ask him to open a specific UDP port for you, 
> at least on the side that has the fixed address and has to receive the 
> first packet.  The other side may be able to get by with a firewall that 
> permits outbound packets with a timeout for the matching reply if you 
> use the keepalive option.

I will stop arguing about this, since IMHO it looks not promising.

FWIW the setup here is:

- the firewall is not on the server side, but the client side.  Outgoing 
  traffic is limited.

- since I want to avoid the restrictions I think are unfair, I will _not_ 
  ask any admin to open a UDP port for me.  The consequence, as you can 
  easily guess, would be an even more restrictive firewall.  Thank you 
  very much.  And no, I do not want to do any illegal things here: I 
  cannot even connect to svn://.

Yes, I know.  Real-world problems.  Baah.


