<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Selectively firewalling OpenVPN users</title>
	<atom:link href="http://darkness.codefu.org/wordpress/2006/03/03/228/feed" rel="self" type="application/rss+xml" />
	<link>http://darkness.codefu.org/wordpress/2006/03/03/228</link>
	<description></description>
	<pubDate>Thu, 20 Nov 2008 17:25:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: serge wautier</title>
		<link>http://darkness.codefu.org/wordpress/2006/03/03/228#comment-12073</link>
		<dc:creator>serge wautier</dc:creator>
		<pubDate>Tue, 30 Jan 2007 14:47:07 +0000</pubDate>
		<guid isPermaLink="false">http://darkness.codefu.org/wordpress/2006/03/03/228#comment-12073</guid>
		<description>Thanks so much for sharing your experience.

One question regarding TAP: I want to create a "virtual" LAN of OpenVPN users: They must be able to see each other but they don't need access to the server's LAN (except for a website on the VPN server itself). I want the packets to go through the server's kernel to perform MAC-based custom filtering (I'll save you the why because it's fairly long) hence no --client-to-client.

Do I absolutely have to use bridging since I don't need the VPN clients to access the server LAN (only the other VPN clients)?

Since I didn't receive any reply on the OpenVPN ML, I thought I'd ask your help.

TIA,

Serge.

PS: BTW there's a strange bug in this comment edit box (Browser=IE6): When you type, the box widens to just a little more than the browser's width makes it difficult to re-read what you just type!</description>
		<content:encoded><![CDATA[<p>Thanks so much for sharing your experience.</p>
<p>One question regarding TAP: I want to create a &#8220;virtual&#8221; LAN of OpenVPN users: They must be able to see each other but they don&#8217;t need access to the server&#8217;s LAN (except for a website on the VPN server itself). I want the packets to go through the server&#8217;s kernel to perform MAC-based custom filtering (I&#8217;ll save you the why because it&#8217;s fairly long) hence no &#8211;client-to-client.</p>
<p>Do I absolutely have to use bridging since I don&#8217;t need the VPN clients to access the server LAN (only the other VPN clients)?</p>
<p>Since I didn&#8217;t receive any reply on the OpenVPN ML, I thought I&#8217;d ask your help.</p>
<p>TIA,</p>
<p>Serge.</p>
<p>PS: BTW there&#8217;s a strange bug in this comment edit box (Browser=IE6): When you type, the box widens to just a little more than the browser&#8217;s width makes it difficult to re-read what you just type!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
