TCPOnly obsolete? Maybe not

Nick Hibma nick at anywi.com
Wed Jun 18 15:18:30 CEST 2014


Guus,

[tinc version 1.0.24]

Consider the case where you have the following setup

	client	-	fw	-	server

The client and server successfully setup a tunnel and UDP communication starts to happen. Then the client shuts up and the server only needs to send data to the client if the remote tool accesses the client’s UI.

If the firewall times out the NAT UDP hole, the server has a problem: The UDP tunnel has been marked as possible, but the UDP tunnel does no longer work because the fw has timed out the UDP hole it punched.

PING/PONG packets are sent on the meta channel, so that is not a solution.

My suggestion is to remove the word ‘obsolete’ from the man page. And perhaps reconsider what could be done about the above.

Nick Hibma
-- 
AnyWi Technologies BV
E: nick at anywi.com
T: +31 (0)71 71 18 306
M: +31 (0)6 14433161

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.tinc-vpn.org/pipermail/tinc/attachments/20140618/880c4a78/attachment.html>


More information about the tinc mailing list