On Sat, Aug 31, 2013 at 10:27:55AM -0700, Nikolaus Rath wrote:

> What I want to do is be able to talk to a tinc server on port 443
> (https) using just TCP, so that the client has the best possible chance
> of making it through any overly restrictive firewalls imposed by some
> WiFi hotspots.
> 
> However, I still want to be able to serve regular https on the same
> server. Thus the idea of adding some iptables rule on the server that
> identify tinc packets and locally redirect those to the regular tinc
> port (while everything else reaches the webserver as usual).
> 
> So I think as long as my rule is specific enough to distinguish tinc and
> TLS, I should be good.

In that case, you can just match the "0 " at the start of the connection, you
don't have to look further. Instead of using iptables, you could also have a
look at sslh:

http://www.rutschle.net/tech/sslh.shtml

-- 
Met vriendelijke groet / with kind regards,
     Guus Sliepen <[email protected]>

Attachment: signature.asc
Description: Digital signature

_______________________________________________
tinc mailing list
[email protected]
http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc

Reply via email to