Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 25th, 2012, 08:17 PM
notthatguy's Avatar
notthatguy notthatguy is offline
Infrequent Poster
 
Join Date: Apr 2012
Posts: 28
Default Notice: TOR Does NOT Automatically Connect Through VPN

Well this is a bit of a strange issue, I use a VPN service and never have bothered running TOR on it as I have no need. Out of boredom today I tried it and here's the situation. I have my Comodo Firewall set to block internet access to certain software in the case my VPN disconnects. This has been tried and true dozens of times and has NEVER caused me any problems.

But when I attempted to set this settings to the Browser Bundle, I was unable to connect. But if I removed the "VPN Only" rules on the firewall it would connect no problem. This leads me to believe that TOR is NOT routed through the VPN.

I use Open VPN for my service, anyone know any way to force it to run through the VPN? Because it seems to go around it.

I figured I'd better post this on Wilders as many people in the past have just stated to run it after connecting to your VPN. Which obviously is NOT the case.

Last edited by notthatguy : September 25th, 2012 at 08:31 PM.
  #2  
Old September 25th, 2012, 09:36 PM
CasperFace's Avatar
CasperFace CasperFace is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 200
Default Re: Notice: TOR Does NOT Automatically Connect Through VPN

You should be able to run Tor after connecting to your VPN with no problem. Perhaps your firewall rules just need some adjusting. In particular, Tor and its components need access to the loopback zone on the local network in order to function correctly. Try this rule set instead:

tbb-firefox.exe
  • Allow TCP Out From MAC Any To IP 127.0.0.1 Where Source Port Is Any And Destination Port Is Any
tor.exe
  • Allow TCP Out From [VPN Only] To MAC Any Where Source Port Is Any And Destination Port Is Any
  • Allow TCP Out From MAC Any To IP 127.0.0.1 Where Source Port Is Any And Destination Port Is Any
vidalia.exe
  • Allow TCP Out From MAC Any To IP 127.0.0.1 Where Source Port Is Any And Destination Port Is 9051
Don't worry about those "MAC Any" connections to 127.0.0.1 - that IP address only exists on the local machine, so it is safe (and necessary). The actual connections to external internet addresses are handled exclusively by the "tor.exe" application. By implementing that first rule for tor.exe, you are effectively binding the connection to your VPN zone, so there won't be any leaks.
  #3  
Old September 26th, 2012, 05:05 PM
notthatguy's Avatar
notthatguy notthatguy is offline
Infrequent Poster
 
Join Date: Apr 2012
Posts: 28
Default Re: Notice: TOR Does NOT Automatically Connect Through VPN

Casper would you mind going over a small tutorial on how to do that? My selections in Comodo look nothing like what you've written there so I'm obviously doing something wrong. Not sure how to implement the MAC any rule even.

Any help would be appreciated.
  #4  
Old September 26th, 2012, 07:49 PM
CasperFace's Avatar
CasperFace CasperFace is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 200
Default Re: Notice: TOR Does NOT Automatically Connect Through VPN

There's probably more than one way to do it. What I usually do is just create rules on the fly, meaning I allow (or block) whatever the application is asking for, and then fine-tune the rules to be more specific (if necessary).

Not really sure if I can explain it any better, but I'll try posting some screen shots.

Firewall Behavior Settings

General Settings
Firewall Security Level = Custom Policy
Create rules for safe applications = Checked
Alert Settings
Alert Frequency Level = "Very High"
Network Security Policy
Application Rules (Summary):

Name:  a.jpg
Views: 463
Size:  38.4 KB

Example Rule #1 for tor.exe:
Allow TCP Out From [IP range or network zone for VPN] To MAC Any Where Source Port Is Any And Destination Port Is Any

Click image for larger version

Name:	bh.jpg
Views:	6
Size:	109.6 KB
ID:	234754

Example Rule #2 for tor.exe:
Allow TCP Out From MAC Any To IP 127.0.0.1 Where Source Port Is Any And Destination Port Is Any

Click image for larger version

Name:	ch.jpg
Views:	2
Size:	104.2 KB
ID:	234755

Last edited by CasperFace : September 26th, 2012 at 08:58 PM.
  #5  
Old September 27th, 2012, 12:19 PM
notthatguy's Avatar
notthatguy notthatguy is offline
Infrequent Poster
 
Join Date: Apr 2012
Posts: 28
Default Re: Notice: TOR Does NOT Automatically Connect Through VPN

Wow Casper that is more than I could have asked for! Thank you!
  #6  
Old September 27th, 2012, 02:25 PM
popcorn's Avatar
popcorn popcorn is offline
Frequent Poster
 
Join Date: Apr 2012
Posts: 237
Default Re: Notice: TOR Does NOT Automatically Connect Through VPN

Quote:
Originally Posted by CasperFace
There's probably more than one way to do it. What I usually do is just create rules on the fly, meaning I allow (or block) whatever the application is asking for, and then fine-tune the rules to be more specific (if necessary).

Not really sure if I can explain it any better, but I'll try posting some screen shots.

Firewall Behavior Settings

General Settings
Firewall Security Level = Custom Policy
Create rules for safe applications = Checked
Alert Settings
Alert Frequency Level = "Very High"
Network Security Policy
Application Rules (Summary):

Attachment 234753

Example Rule #1 for tor.exe:
Allow TCP Out From [IP range or network zone for VPN] To MAC Any Where Source Port Is Any And Destination Port Is Any

Attachment 234754

Example Rule #2 for tor.exe:
Allow TCP Out From MAC Any To IP 127.0.0.1 Where Source Port Is Any And Destination Port Is Any

Attachment 234755

also
thanx
Popcorn
__________________
CIS 6
ExploitShield beta
Virtually Virtual
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums