iptables AS0_IN_PRE questions.

Business solution to host your own OpenVPN server with web management interface and bundled clients.
Post Reply
seandex
OpenVpn Newbie
Posts: 14
Joined: Mon Jun 20, 2016 5:00 pm

iptables AS0_IN_PRE questions.

Post by seandex » Mon Feb 26, 2018 12:51 am

Are these necessary if I don't follow RFC1918 on the client?

AS0_IN all -- anywhere link-local/16
AS0_IN all -- anywhere 192.168.0.0/16
AS0_IN all -- anywhere 172.16.0.0/12
AS0_IN all -- anywhere 10.0.0.0/8

thinking about to drop it because of spoofing and bad ip attacks.
what do you think?

User avatar
novaflash
OpenVPN Inc.
Posts: 1073
Joined: Fri Apr 13, 2012 8:43 pm

Re: iptables AS0_IN_PRE questions.

Post by novaflash » Fri Mar 02, 2018 11:29 am

Hi seandex,

As far as I know it's not supported to manually alter iptables rules on Access Server, you may cause unexpected problems. But I mean, sure, if you think you know what you're doing, go ahead and try it. Test everything afterwards and if everything checks out, great. But beware that whenever you make changes to the configuration or the access server restarts or reloads settings, these rules will very likely be added in again automatically.
I'm still alive, just posting under the openvpn_inc alias now as part of a larger group.

Post Reply