Re: [gentoo-user] openvpn experience, anyone?

2022-09-19 Thread n952162

On 9/18/22 14:23, William Kenworthy wrote:


On 18/9/22 16:26, n952162 wrote:


On 9/18/22 09:52, William Kenworthy wrote:


On 18/9/22 15:26, n952162 wrote:

Hello all,

I want to ssh over my openvpn connection, and I can't do it, the
connection times out.

I saw a reference to gentoo in the openvpn scripts in /etc/openvpn and
thought maybe somebody here  knows something about this.

Earlier my institution recommended openconnect, and I was able to use
ssh to login in to a host with no problem.

Then, for some reason (licensing?), we were switched to openvpn, which
works for xfreerdp but not for ssh.

I don't have control over the institution's firewall (but I do have
for
the host itself)

Perhaps when installing the new service, they tightened up the
firewall
rules.  But maybe there's a configuration screw I can turn, or ...
maybe
a USE flag?

- - down-root : Enable the down-root plugin
 - - examples  : Install examples, usually source code
 - - inotify   : Enable inotify filesystem monitoring support
 - - iproute2  : Enabled iproute2 support instead of net-tools
 + + lz4   : Enable support for lz4 compression (as implemented in
app-arch/lz4)
 + + lzo   : Enable support for lzo compression
 - - mbedtls   : Use mbed TLS as the backend crypto library
 + + openssl   : Use OpenSSL as the backend crypto library
 + + pam   : Add support for PAM (Pluggable Authentication
Modules)
- DANGEROUS to
 arbitrarily flip
 - - pkcs11    : Enable PKCS#11 smartcard support
 + + plugins   : Enable the OpenVPN plugin system
 - - systemd   : Enable use of systemd-specific libraries and features
like socket
 activation or session tracking
 - - test  : Enable dependencies and/or preparations necessary to
run tests
 (usually controlled by FEATURES=test but can be
toggled independently)

TIA



ssh and openvpn work well together.  However I am doing most of the
work using my own configs - gentoo tries to be too clever with its vpn
networking and Ive never been able to get it to work
reliably/acceptably.  On some sites I have to use port 443 (https) to
get through, and in extreme cases double wrap in ssl (using a mix of
proxytunnel (windows host), stunnel and sslh) to disguise its a vpn
but still separate it from regular https traffic on my firewall.  You
will need to figure out where the ssh is getting blocked/stripped out
- is openvpn your endpoint or theirs?

BillK





I don't understand that question: "is openvpn your endpoint or theirs" -
don't both sides have an endpoint on the tunnel?

That would have been a class idea, using the https port ...
unfortunately, there's a web server running on that machine... it's not
being used, however ... hmmm.

Wow: "in extreme cases double wrap in ssl (using a mix of proxytunnel
(windows host), stunnel and sslh) to disguise its a vpn but still
separate it from regular https traffic on my firewall." - sounds totally
cool, except I have no idea what it means... which concept should I
start with?

- proxytunnel

- sslh

- double wrapping in ssl


1. Do you have control over both openvpn endpoints?  Typically in a
roadwarrior setup the company IT dept owns one and you don't get
access to it which can make it very difficult to see whats going on -
if you can access the configs of both ends its much easier. The
firewall you mention might be dropping ssh packets exiting the tunnel
if its hosting an endpoint that is subject to the firewall?  Routing
multiple hops past the vpn endpoint can be another issue with openvpn.



Ah, now I have a  better understanding of the question - yes,
unfortunately, the vpn goes to the institution's intranet.  I control
the client and the host, and the link to the institution, but the remote
endpoint of the tunnel is not in my control.




2. SSL packets have identifiers in the headers that indicate the type
of traffic within - sslh is a multiplexor that detects openvpn,
openssl, openssh etc. via the ssl packet headers (does not need to see
into the encryption to do this) and redirects the packets to different
hosts/ports as applicable - e.g, ssl web traffic to your web server
and openvpn ssl to to the vpn concentrator even though it all comes in
as ssl on port 443.



Okay, that gets me a lot closer.   Thank you.



3a. Before retiring I was working within various seriously locked down
networks and needed to reach my own home server - some of the
commercial firewalls are able to break and examine ssl streams, or
identify it was openvpn on port 443 and block it.  If you are using a
commercial certificate with openvpn this may be happening.

3b. If you own/host both ends of the vpn tunnel on your own machines,
use the end-to-end encryption options, and a private certificate. By
feeding the openvpn ssl stream through something like proxytunnel you
are encrypting the stream a second time with https characteristics
which gets around this to some degree (if they do bother break out the
ssl, they are 

Re: [gentoo-user] new machine : a lot clearer

2022-09-19 Thread Philip Webb
220915 Mark Knecht wrote:
> I don't think PCIe 4.0 would, in this sort of machine,
> have much to do with compile times.
> This level of machine has an NVMe flash drive for the system disk.
> My machine has 2 x 1 TB NVMe SSDs and no mechanical drives.

Thanks lots : that's the crucial advice I was looking for.

I've reviewed what's available at local stores again (Downtown is closest) :

CPU + Mobo : available 220914
 ( D downtown  M midtown  N NYork  S Scarboro  d delivery ; o openbox ) :

CPU : must incl graphix + cooler

AMD :

  (1) CPAMD00130 : Ryzen 5 : 5600G : $ 187 (350)
   6-Core/12-Thread : 7 nm : PCIe 3.0
   Socket AM4 : 3.9 GHz , boost 4.4 GHz
   Radeon Graphics : Wraith Stealth Cooler : 65 W 
  Available 220915 : D  5   M  5   N 10   S  7   d  y

  (2) CPAMD00141 : Ryzen 5 : 4600G : $ 200
   6-Core/12-Thread : 7 nm : PCIe ? (sb 3.0)
   Socket AM4 : 3.7 GHz , boost 4.2 GHz 
   Radeon Graphics : Wraith Stealth Cooler : 65 W
  Available 220915 : D  1   M  -   N  1   S  -   d  y

  (3) CPAMD00131 : Ryzen 7 : 5700G : $ 310 (470) : *** looks best ***
   8-Core/16-Thread : 7 nm : PCIe 3.0
   Socket AM4 : 3.8 GHz , boost 4.6 GHz 
   Radeon Graphics : Wraith Stealth cooler : 65 W
  Available 220915 : D  1   M  1   N  1   S  1   d  y

Intel : lowest price w  8  cores ;
  doesn't look competitive : 14 nm ; no fan ; $ 110 > AMD 00131 ;
  installation challenges : Intel pins are on the mobo, so damage easier ;
   it used to be more of a challenge to fit the fan on the CPU w Intel.

  (1) CPINT00159 : Intel Core i9-11900K : $ 420 (600) : *** not attractive ***
   8-Core/16-Thread : 14 nm : Socket LGA 1200
   (Intel 500 + select 400 Series) Unlocked
   3.5 GHz , turbo 5.3 GHz : 11th
   UHD Graphics 750 : 125 W : no cooler ?
  Available 220919 : D  2   M  1   N  -   S  -   d  y

Mobo: AMD : *** not clear there's much difference ***

  (1) MBGIG00135 : Gigabyte : X570 AORUS ELITE : $ 220 (300)
   12+2 Phase Digital VRM with DrMOS
   Advanced Thermal Design with Enlarge Heatsink
   Dual PCIe 4.0 M.2 w Single Thermal Guard
   Intel GbE LAN w cFosSpeed, Front USB Type-C, RGB Fusion 2.0
  Available 220914 : D  3   M  4   N  6   S  3   d  y

  (2) MBGIG00261 : Gigabyte : X570S AORUS ELITE : $ 250 (330)
   AX AMD X570 DDR4
   Wi-Fi 6E : Bluetooth
   PCIe 4.0 M.2 : USB 3.2 : ATX
  Available 220914 : D  4   M  2   N  9   S  2   d  y

  (3) MBGIG00260 : Gigabyte : X570S AORUS PRO : $ 280 (390)
   AX Socket AM4 AMD X570 DDR4
   Wi-Fi 6 Bluetooth
   PCIe 4.0 M.2 : USB 3.2 : ATX
  Available 220914 : D  2   M  2   N  5   S  1   d  y

  (4) MBGIG00242 : Gigabyte : X570S AERO G : $ 300 (470)
   AMD X570 : 4 x DDR4 DIMM : 128 GB
   Intel Wi-Fi 6E
   PCIe 4.0 : USB Type-C M.2
  Available 220914 : D  2   M  1   N  1   S  1   d  y

-- end of review --

Intel seems to offer inferior product for higher price : comparison only.

AMD : I want  8  cores with  16  threads.
I want graphics + cooling included with the CPU.
PCIe 3.0 is adequate for what I do : with  32 GB  memory
everything sb compilable there with no need to use the SSD ;
ANB5 (my present machine) has DDR3, so ANB6's DDR4 wb faster.
Price differences aren't important in themselves among these choices.
There is free WiFi where I live, tho' landline mb better for security.

Thanks for the advice so far : further comments are very welcome.

-- 
,,
SUPPORT ___//___,   Philip Webb
ELECTRIC   /] [] [] [] [] []|   Cities Centre, University of Toronto
TRANSIT`-O--O---'   purslowatchassdotutorontodotca