On Sat, Aug 31, 2013 at 10:27:55AM -0700, Nikolaus Rath wrote: > What I want to do is be able to talk to a tinc server on port 443 > (https) using just TCP, so that the client has the best possible chance > of making it through any overly restrictive firewalls imposed by some > WiFi hotspots. > > However, I still want to be able to serve regular https on the same > server. Thus the idea of adding some iptables rule on the server that > identify tinc packets and locally redirect those to the regular tinc > port (while everything else reaches the webserver as usual). > > So I think as long as my rule is specific enough to distinguish tinc and > TLS, I should be good.
In that case, you can just match the "0 " at the start of the connection, you don't have to look further. Instead of using iptables, you could also have a look at sslh: http://www.rutschle.net/tech/sslh.shtml -- Met vriendelijke groet / with kind regards, Guus Sliepen <[email protected]>
signature.asc
Description: Digital signature
_______________________________________________ tinc mailing list [email protected] http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc
