[ previous ] [ next ] [ threads ]
 From:  Chris Buechler <cbuechler at gmail dot com>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] VPN Problem help !!
 Date:  Thu, 23 Sep 2004 19:18:34 -0400
On Thu, 23 Sep 2004 07:58:09 -0600, Luu Duong <xxxxxx at medialogic dot ca> wrote:
> Did you try unchecking the option for "Block private networks" for the
> WAN interface. This would be a security risk normally.

Don't do this, it's not necessary.  The VPN traffic coming in on the
WAN will be coming from the public IP of the remote VPN gateway.  It
doesn't have a source of a private IP until it's decrypted by the
m0n0wall and passed onto the LAN, which is after it's passed through
the WAN firewall rules.