IRC log for #gllug on 20100830

00:06.33*** join/#gllug Leeds (~richardc@n219078058021.netvigator.com)
02:41.32*** join/#gllug Leeds (~richardc@www.scorefive.com)
02:46.14*** join/#gllug boudiccas (~boudiccas@unaffiliated/boudiccas)
07:51.05*** join/#gllug zplinux (~zplinux@213.8.57.217)
08:35.41zplinuxhmm, hi all
08:35.45zplinuxis it possible to have many clients connect to one server and not have them talk to each other?
08:36.01zplinuxI am reffering to openvpn
08:36.04zplinuxand I dont mean the client-to-client option
08:36.40jpdsDon't think so; you'd probably have to put them on their own VLANs.
08:38.13zplinuxhow many vlans can I have on my pc?
08:39.26zplinuxthanks jpds
08:40.11jpdszplinux: They usually go on switchen.
08:43.41Leedszplinux: isn't that the point of the client-to-client option?
08:44.21zplinuxhi LEEDS!
08:44.33zplinuxem
08:44.46zplinuxnot sure
08:44.59Leedsor, well, obviously its absence
08:45.31zplinuxI mean the idea is to allow clients to download updates when a firewall blocks incoming connection
08:45.47Leedswhat does that have to do with clients seeing each other?
08:46.03zplinuxyet from the security perspective, we dont want one hacked client to enter the whole system
08:46.17zplinuxLeeds: not sure
08:46.45zplinuxI mean I dont want to allow a hacked client to have access to any other system
08:47.11zplinuxkind of ptp from each cleint to our server
08:47.26zplinuxinfact I only need one line in the route
08:47.35zplinuxhmm
08:48.34zplinuxI think I just need to try it out
08:48.48zplinuxseems I can do this with the avail tools
08:48.54antiphaseYou'd need to use a VLAN per switch port or a switch with port protection. You can't do it with software if you allow users any sort of system access
08:49.35zplinuxcan't I use ebtales?
08:49.40antiphaseAnd that still potentially allows UDP from one client to another unless you also put ACLs between your VLANs or put everyone on a firewall and have some horrendous config
08:50.11antiphaseIt's the sort of question that you have to ask why you're asking, because it suggests some sort of elementary architectural problem
08:50.37antiphases/UDP/unidirectional traffic/
08:50.43antiphaseguzzles moar coffee
08:51.22antiphaseebtables is for controlling traffic between network segments
08:51.51antiphaseYou're talking about clients who are potentially on the same network, which is why you end up having to have a network per client so you can control the inter-network traffic
08:52.36antiphasereads the question again
08:52.46antiphaseDo you just mean openvpn?
08:52.56zplinuxyes I do
08:53.46antiphaseIf you haven't got IP forwarding enabled, then the server shouldn't route packets
08:54.17antiphaseOf course if you're using it as a gateway then having IP forwarding enabled is sort of useful :P
08:54.33antiphaseiptables is a possibility though
08:55.04antiphaseI understamd why you asked about ebtables now, but it's unnecessary unless you're using TAP interfaces, which are horrid anyway
08:56.22zplinuxantiphase: ok, how would you solve this common problem
08:56.31antiphaseIs it common?
08:56.54zplinuxyou hold a server in your company that has updates to your costemers
08:57.11zplinuxcostumers
08:57.17antiphasecustomers :P
08:57.42antiphaseI'd firstly ask why openvpn would be your choice for just moving some data about
08:57.51antiphaserather than HTTPS
08:58.07antiphase(over the public internet)
08:58.14zplinuxthey are connected to the internet using NAT and you can't open a forward port there
08:58.31antiphaseThey can still connect to your server then
09:00.08zplinuxI want the connection to be secure
09:00.13zplinuxhttps is a nice idea
09:00.43zplinuxonly need a script to dowload updates and run them
09:01.11zplinuxbut I also want to offer interactive support
09:01.19zplinuxso I do need a way in
09:01.24antiphaseWhat does that involve?
09:01.30zplinuxsshing in
09:03.17antiphaseSo you're back to a VPN again
09:04.24zplinuxyes
09:04.34zplinuxlet try it here
09:04.58zplinuxI will be back when I know what to ask
09:39.55*** join/#gllug mikejw (~android@212.183.140.0)
10:04.08halimorning
10:04.16halif*cking notting hill carneval outside my window
10:05.10haliat least the bring good food
12:11.59*** join/#gllug eje211 (~quassel@82-71-45-200.dsl.in-addr.zen.co.uk)
12:12.32eje211Hey! I'm looking to buy a Netbook with Linux or without Windows in London. Does such a thing still exist, and if so, where?
12:13.46*** join/#gllug eje211 (~quassel@82-71-45-200.dsl.in-addr.zen.co.uk)
12:30.00*** join/#gllug andrewblack (~andrew@vm.black1.org.uk)
12:38.31eje211Hey! I'm looking to buy a Netbook with Linux or at least without Windows in London. Does such a thing still exist, and if so, where?
13:32.44*** join/#gllug sabinef72 (~sabinef72@barcelone.ipv6.popipo.fr)
14:41.23*** join/#gllug Leeds (~richardc@n219078058021.netvigator.com)
15:31.28*** join/#gllug andrewblack (~andrew@vm.black1.org.uk)
16:04.44*** join/#gllug Barry-Nichols (~Barry@cpc3-bsfd4-0-0-cust332.5-3.cable.virginmedia.com)
17:12.26*** join/#gllug DiscordianUK (~ch@fedora/DiscordianUK)
17:43.26*** join/#gllug andrewblack (~andrew@vm.black1.org.uk)
17:46.04*** join/#gllug MessedUpHare (~stewart@cpc8-acto3-2-0-cust6.4-2.cable.virginmedia.com)
18:32.51*** join/#gllug DiscordianUK (~ch@fedora/DiscordianUK)
22:46.16*** join/#gllug shai (~Shai@l192-117-110-233.cable.actcom.net.il)

Generated by irclog2html.pl Modified by Tim Riker to work with infobot.