New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TOR connection fails when using a VPN #2541

Closed
john6611 opened this Issue Dec 26, 2016 · 3 comments

Comments

Projects
None yet
2 participants
@john6611

Qubes OS version (e.g., R3.2):

3.2

Affected TemplateVMs (e.g., fedora-23, if applicable):

fedora-23 / debian08


Connection = dom0 > sys-net > sys-firewall > VPN (proxyvm) > sys-whonix > anon-whonix

TOR through the TOR browser works fine for aslong as I don't turn on the VPN
As soon as I turn on the VPN I can't connect to TOR anymore (tried restarting TOR & VM's)

Tried both on debian-8 and fedora-23 and proxyVM with both mullvad and airvpn
The VPN connection works fine (testing with firefox in the VPN proxyVM)

Is this is an actual bug or am I overlooking something?

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Dec 27, 2016

Member

Connection = dom0 > sys-net > sys-firewall > VPN (proxyvm) > sys-whonix > anon-whonix

I think you mean this, instead:

anon-whonix > sys-whonix > VPN (ProxyVM) > sys-firewall > sys-net > local network / internet

For simplicity, I'm going to refer to "VPN (ProxyVM)" as sys-vpn.

TOR through the TOR browser works fine for aslong as I don't turn on the VPN
As soon as I turn on the VPN I can't connect to TOR anymore (tried restarting TOR & VM's)

I presume you mean that if you set the NetVM of sys-whonix to sys-firewall, then it works.

Tried both on debian-8 and fedora-23 and proxyVM with both mullvad and airvpn
The VPN connection works fine (testing with firefox in the VPN proxyVM)

That's not the the correct way to test sys-vpn. Instead, use a non-Whonix (vanilla Fedora or Debian) AppVM, and set sys-vpn as the AppVM's NetVM, then test the connection. Confirm that websites see your IP address as one belonging to your VPN provider.

Is this is an actual bug or am I overlooking something?

Make sure you've thoroughly read the documentation:

https://www.whonix.org/wiki/Tunnels/Connecting_to_a_VPN_before_Tor#Separate_VPN-Gateway

Member

andrewdavidwong commented Dec 27, 2016

Connection = dom0 > sys-net > sys-firewall > VPN (proxyvm) > sys-whonix > anon-whonix

I think you mean this, instead:

anon-whonix > sys-whonix > VPN (ProxyVM) > sys-firewall > sys-net > local network / internet

For simplicity, I'm going to refer to "VPN (ProxyVM)" as sys-vpn.

TOR through the TOR browser works fine for aslong as I don't turn on the VPN
As soon as I turn on the VPN I can't connect to TOR anymore (tried restarting TOR & VM's)

I presume you mean that if you set the NetVM of sys-whonix to sys-firewall, then it works.

Tried both on debian-8 and fedora-23 and proxyVM with both mullvad and airvpn
The VPN connection works fine (testing with firefox in the VPN proxyVM)

That's not the the correct way to test sys-vpn. Instead, use a non-Whonix (vanilla Fedora or Debian) AppVM, and set sys-vpn as the AppVM's NetVM, then test the connection. Confirm that websites see your IP address as one belonging to your VPN provider.

Is this is an actual bug or am I overlooking something?

Make sure you've thoroughly read the documentation:

https://www.whonix.org/wiki/Tunnels/Connecting_to_a_VPN_before_Tor#Separate_VPN-Gateway

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Jan 12, 2017

Member

@john6611: Did my previous message help? Does the issue persist?

Member

andrewdavidwong commented Jan 12, 2017

@john6611: Did my previous message help? Does the issue persist?

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Dec 16, 2017

Member

Closing this for now due to the lack of response. If you revisit the matter in the future, or if anyone would like the issue to remain open, please leave a comment, and we'll be happy to reopen this. Thank you.

Member

andrewdavidwong commented Dec 16, 2017

Closing this for now due to the lack of response. If you revisit the matter in the future, or if anyone would like the issue to remain open, please leave a comment, and we'll be happy to reopen this. Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment