Re: Openvpn on FreeBSD 7



--- On Tue, 6/10/08, Nejc Škoberne <nejc@xxxxxxxxxxxx> wrote:


Actually I don't think you can do the same thing with a
tunnel. You have
to use a different IP addresses for the tunnel itself. Have
you read the
OpenVPN manual?

Yes, I did: 'tcpdump -i tun0'. Nothing shows
up on the server, but on
the client (OS X) I can see the pings being sent.

This means that there is a problem with the OpenVPN
connection. Can you show
the tail of your logs on both sides?

proto tcp

Why are you using TCP anyway?

Bye,
Nejc

Hi Andrew, Nejc, All

I just built my first FreeBSD 7.0 machine to test OpenVPN on it
It was a nice way to review/fix my OpenVPN page

I forgot to stress how important the sysctl setting is for net.inet.ip.forwarding

The default is disabled (0) and I to could not connect beyond the OpenVPN server

I'm editing the page now to include something like this

Make sure IP Forwarding is enabled
Check it with
sysctl -a |grep net.inet.ip.f

Set it with
sysctl inet.inet.ip.forwarding=1
or
Alternatively set it by adding this to /etc/sysctl.conf
net.inet.ip.forwarding=1

I hope this helps

Take care

Steve



_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: VPN Remote Access
    ... Al Jarvi (MS-MVP Windows Networking) ... Server or going the OpenVPN route. ... Pro Remote Desktop through the tunnel to access the desktops. ...
    (microsoft.public.windowsxp.network_web)
  • Re: [Fedora] Re: VPN
    ... I'll share my working OpenVPN server config with you. ... I have mine set to use PAM authentication (meaning they'd need an account on your F10 server, LDAP or otherwise) and ignores client certificates, which could be bad, but it's just me and it's passworded with the user account access. ... # the firewall for the TUN/TAP interface. ...
    (Fedora)
  • fc5 + openvpn + not routing across the tunnel..
    ... I have configured openvpn in my lab ... bad source address from client, ... the server is configured as follows ... # This config item must be copied to ...
    (Fedora)
  • Re: SonicWall vs. WatchGuard Vergleich
    ... Admin bin, habe ich in anderen Bereichen auch schon mitbekommen, dass ... Bei openVPN nimmst Du Dir einen IPcop plus Zerina ... 20 Mann Firma wegen Administrativen Aufwand nicht lohnt, ... Natürlich ist es riskanter einen SMTP server zu fahren. ...
    (de.comp.security.firewall)
  • OpenVPN -- bridges -- Firewall -- Netzwerkproblem
    ... OpenVPN Netzwerk mit Defaultroute über Openvpn (tap Interface im bridge ... dem Internet anpingbar, der client kann den server anpingen. ...
    (comp.os.linux.security)