-
Notifications
You must be signed in to change notification settings - Fork 56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vpn leaks imcpv6, mdns, arp, lldp, dns #182
Comments
Does this only happen when you use FORCED_LOCAL_INTERFACE to force all local traffic? |
I believe this is dpinger doing its uptime thing via ubios-udapi-server. I think it does the same with and without setting FORCED_LOCAL_INTERFACE. |
No I know the pings are from dpinger, but does this traffic go through the VPN even when you don't use FORCED_LOCAL_INTERFACE? |
The above Wireshark screenshot is from an adapter connected to the UDM WAN port with FORCED_LOCAL_INTERFACE enabled. |
Okay, so this script isn't leaking anything then? Do you just want to stop dpinger from working at all, or do you want to force all traffic from the UDM, but exempt dpinger from going out the VPN? You can definitely stop dpinger, but then you won't have the uptime or latency info on the Unifi Network dashboard, and it might mess with Unifi OS recognizing if a connection is up or not. |
Ideally, I'd like to have nothing escaping the VPN. Everything going through the WAN interface to be encapsulated in the tunnel. Basically #181. But this issue is because I expected that FORCED_LOCAL_INTERFACE=eth8 would not leak the stuff in the screenshot above (+lldp, mdns, imcpv6, etc). |
@peacey, any idea how to not leak this DNS traffic on reboot when FORCED_LOCAL_INTERFACE is set to the WAN interface? |
@peacey, do you think a firewall rule could filter out this traffic if it's not going on udp.port == 51820? |
some of these probably can't be stopped for the device to work, however... can DNS resolution of ping domains like these be stopped?
and of course, if the noise of any of the other protos could also be removed/reduced
The text was updated successfully, but these errors were encountered: