Can OpenVPN (Linux) connect through a jump server?












0















I use MacOS at work, where I connect to a VPN (using Tunnelblick). We use a "jumpbox" to proxy requests to the VPN server itself. I have an ovpn file, username and password for the VPN, plus a username and pem file to get into the jump server.



In Tunnelblick, there's an option for assigning a proxy server and username/cert file. I don't see such an option using OpenVPN on Linux (Fedora 29) using the default network manager GUI for KDE (kcm_networkmanagement). Is there a way to use a jump server in Fedora's OpenVPN client? If not, is there another OpenVPN client that might work?



I've tried Frohu client, but I don't see any jump server / proxy options there. I've also tried using OpenVPN from the command line, but openvpn --config never asks for a proxy option, and the man page help doesn't seem to support jump servers, as far as I can tell.










share|improve this question























  • Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

    – dirkt
    Feb 20 at 7:02











  • Possible duplicate of OpenVPN connection through SSH tunnel

    – crimson-egret
    Feb 20 at 22:21
















0















I use MacOS at work, where I connect to a VPN (using Tunnelblick). We use a "jumpbox" to proxy requests to the VPN server itself. I have an ovpn file, username and password for the VPN, plus a username and pem file to get into the jump server.



In Tunnelblick, there's an option for assigning a proxy server and username/cert file. I don't see such an option using OpenVPN on Linux (Fedora 29) using the default network manager GUI for KDE (kcm_networkmanagement). Is there a way to use a jump server in Fedora's OpenVPN client? If not, is there another OpenVPN client that might work?



I've tried Frohu client, but I don't see any jump server / proxy options there. I've also tried using OpenVPN from the command line, but openvpn --config never asks for a proxy option, and the man page help doesn't seem to support jump servers, as far as I can tell.










share|improve this question























  • Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

    – dirkt
    Feb 20 at 7:02











  • Possible duplicate of OpenVPN connection through SSH tunnel

    – crimson-egret
    Feb 20 at 22:21














0












0








0








I use MacOS at work, where I connect to a VPN (using Tunnelblick). We use a "jumpbox" to proxy requests to the VPN server itself. I have an ovpn file, username and password for the VPN, plus a username and pem file to get into the jump server.



In Tunnelblick, there's an option for assigning a proxy server and username/cert file. I don't see such an option using OpenVPN on Linux (Fedora 29) using the default network manager GUI for KDE (kcm_networkmanagement). Is there a way to use a jump server in Fedora's OpenVPN client? If not, is there another OpenVPN client that might work?



I've tried Frohu client, but I don't see any jump server / proxy options there. I've also tried using OpenVPN from the command line, but openvpn --config never asks for a proxy option, and the man page help doesn't seem to support jump servers, as far as I can tell.










share|improve this question














I use MacOS at work, where I connect to a VPN (using Tunnelblick). We use a "jumpbox" to proxy requests to the VPN server itself. I have an ovpn file, username and password for the VPN, plus a username and pem file to get into the jump server.



In Tunnelblick, there's an option for assigning a proxy server and username/cert file. I don't see such an option using OpenVPN on Linux (Fedora 29) using the default network manager GUI for KDE (kcm_networkmanagement). Is there a way to use a jump server in Fedora's OpenVPN client? If not, is there another OpenVPN client that might work?



I've tried Frohu client, but I don't see any jump server / proxy options there. I've also tried using OpenVPN from the command line, but openvpn --config never asks for a proxy option, and the man page help doesn't seem to support jump servers, as far as I can tell.







linux ssh vpn fedora openvpn






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Feb 20 at 4:57









taco_burritotaco_burrito

11




11













  • Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

    – dirkt
    Feb 20 at 7:02











  • Possible duplicate of OpenVPN connection through SSH tunnel

    – crimson-egret
    Feb 20 at 22:21



















  • Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

    – dirkt
    Feb 20 at 7:02











  • Possible duplicate of OpenVPN connection through SSH tunnel

    – crimson-egret
    Feb 20 at 22:21

















Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

– dirkt
Feb 20 at 7:02





Without knowing the details of your setup: If you ssh into the jumpbox, use ssh with port forwarding (e.g. -L), point your local OpenVPN to the forwarded local ssh port, see if it works. IIRC ssh only port forwards TCP, so your VPN will need to use TCP, too. Not sure if the automatic setup OpenVPN does will get confused by this, you may have to fiddle with it (disable and replace with manual setup as necessary).

– dirkt
Feb 20 at 7:02













Possible duplicate of OpenVPN connection through SSH tunnel

– crimson-egret
Feb 20 at 22:21





Possible duplicate of OpenVPN connection through SSH tunnel

– crimson-egret
Feb 20 at 22:21










1 Answer
1






active

oldest

votes


















0














This is effectively a duplicate of this other question, for which I gave an answer, though no answer wasn't accepted by the OP.






share|improve this answer























    Your Answer








    StackExchange.ready(function() {
    var channelOptions = {
    tags: "".split(" "),
    id: "3"
    };
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function() {
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled) {
    StackExchange.using("snippets", function() {
    createEditor();
    });
    }
    else {
    createEditor();
    }
    });

    function createEditor() {
    StackExchange.prepareEditor({
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader: {
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    },
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    });


    }
    });














    draft saved

    draft discarded


















    StackExchange.ready(
    function () {
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1407697%2fcan-openvpn-linux-connect-through-a-jump-server%23new-answer', 'question_page');
    }
    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    This is effectively a duplicate of this other question, for which I gave an answer, though no answer wasn't accepted by the OP.






    share|improve this answer




























      0














      This is effectively a duplicate of this other question, for which I gave an answer, though no answer wasn't accepted by the OP.






      share|improve this answer


























        0












        0








        0







        This is effectively a duplicate of this other question, for which I gave an answer, though no answer wasn't accepted by the OP.






        share|improve this answer













        This is effectively a duplicate of this other question, for which I gave an answer, though no answer wasn't accepted by the OP.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Feb 20 at 22:20









        crimson-egretcrimson-egret

        1,350613




        1,350613






























            draft saved

            draft discarded




















































            Thanks for contributing an answer to Super User!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid



            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.


            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1407697%2fcan-openvpn-linux-connect-through-a-jump-server%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            How do I know what Microsoft account the skydrive app is syncing to?

            When does type information flow backwards in C++?

            Grease: Live!